CVE-2017-3526 - log back

CVE-2017-3526 created at 25 Sep 2019 19:31:40
Severity
+ High
Remote
+ Remote
Type
+ Denial of service
Description
+ It was found that the JAXP component of OpenJDK failed to correctly enforce parse tree size limits when parsing XML document. An attacker able to make a Java application parse a specially crafted XML document could use this flaw to make it consume an excessive amount of CPU and memory.
References
+ http://hg.openjdk.java.net/jdk8u/jdk8u/jaxp/rev/756b7a2f20cc
Notes