High severity7.5NVD Advisory· Published Oct 11, 2022· Updated Jun 17, 2026
CVE-2022-41404
CVE-2022-41404
Description
An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.ini4j:ini4jMaven | <= 0.5.4 | — |
Affected products
7- osv-coords4 versionspkg:rpm/opensuse/ini4j&distro=openSUSE%20Tumbleweedpkg:maven/org.ini4j/ini4jpkg:apk/chainguard/druid-compatpkg:apk/wolfi/druid-compat
< 0.5.4-1.1+ 3 more
- (no CPE)range: < 0.5.4-1.1
- (no CPE)range: <= 0.5.4
- (no CPE)range: < 34.0.0-r6
- (no CPE)range: < 34.0.0-r6
- org.ini4j/org.ini4jdescription
Patches
Vulnerability mechanics
References
7- sourceforge.net/p/ini4j/bugs/56/nvdExploitMailing ListThird Party Advisory
- github.com/advisories/GHSA-jr6h-r7vg-f9mcghsaADVISORY
- lists.debian.org/debian-lts-announce/2022/11/msg00037.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-41404ghsaADVISORY
- github.com/Checkmarx/Vulnerabilities-Proofs-of-Concept/tree/main/2022/CVE-2022-41404nvdWEB
- sourceforge.net/p/ini4j/bugs/56ghsaWEB
- sourceforge.net/projects/ini4jghsaWEB
News mentions
0No linked articles in our index yet.