Description
AdaCore Ada Web Services (AWS) before 2.10.2 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
Affected products
- adacore / ada_web_services2.10.1
- adacore / ada_web_services2.10.0 – 2.10.0