
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This vulnerability is tracked as CVE-2023-50570 and has been disputed because the infinite loop occurs only for cases in which the developer supplies invalid arguments, and the product is not intended to always halt for contrived inputs (NVD).
The vulnerability is classified as CWE-835 (Loop with Unreachable Exit Condition - 'Infinite Loop'). It has received a CVSS v3.1 base score of 5.5 (MEDIUM) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H. The issue specifically occurs in the IPAddressBitsDivision component when certain invalid arguments are provided (NVD, FortiGuard).
The vulnerability affects the availability of the system by potentially causing an infinite loop, which could lead to resource exhaustion. However, the impact is limited as it only occurs under specific conditions with invalid input parameters (NVD).
Users are advised to avoid using versions <=5.4.0 of the com.github.seancfoley/ipaddress package (FortiGuard).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."