Uncontrolled Recursion
CVE-2024-58103
Summary
Square Wire versions prior to 5.2.0 does not enforce a recursion limit on nested groups in "ByteArrayProtoReader32.kt" and "ProtoReader.kt".
- LOW
- NETWORK
- NONE
- CHANGED
- NONE
- NONE
- NONE
- LOW
CWE-674 - Uncontrolled Recursion
The product does not properly control the amount of recursion which takes place, consuming excessive resources, such as allocated memory or the program stack.
References
Advisory Timeline
- Published