RULE(RULE ID:337969)

Rule General Information
Release Date: 2024-04-29
Rule Name: Juice Shop api-docs Deserialization Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Juice Shop is a Web application that covers OWASP Top10 vulnerabilities. The Juice Shop /b2b/v2/orders interface has a deserialization vulnerability that can keep an application busy forever, resulting in a denial-of-service attack.
Impact: An attacker can carefully construct malicious serialized data and pass it to the application, and execute the malicious code constructed by the attacker when the application deserializes the object.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.