• CVE-2025-1695

发布时间: 2025年3月6日

修改时间: 2025年4月2日

概要

In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS).  There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS v3 指标

NVD openEuler
CVSS评分 N/A 5.3
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-1272 In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS).  There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 2025年3月6日

影响产品

产品 状态
KY3.4-5A nginx Unaffected
KY3.5.2 nginx Unaffected
V6 nginx Unaffected