The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.
Start learningUpgrade org.apache.neethi:neethi to version 3.2.3 or higher.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in AbstractPolicyOperator during policy normalization. An attacker can force excessive resource consumption by supplying crafted policies that use ExactlyOne aggregation to evade the maximum-alternatives cap while the policy is normalized. The vulnerable normalization path in src/main/java/org/apache/neethi/AbstractPolicyOperator.java processes nested policy components without enforcing a global budget across aggregated ExactlyOne branches, allowing the normalized alternative count to grow far beyond the intended limit. This can exhaust CPU and memory during policy processing and cause service slowdown or outage for applications that parse attacker-controlled policies.