Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-32821

Опубликовано: 03 янв. 2023
Источник: debian

Описание

MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mootoolsunfixedpackage

Примечания

  • https://securitylab.github.com/advisories/GHSL-2020-345-redos-mootools/

  • No plan to fix this upstream as upstream consider it too low impact.

  • Negligible securiy impact

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 3 лет назад

MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.

CVSS3: 6.2
nvd
около 3 лет назад

MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.

CVSS3: 7.5
github
около 3 лет назад

MooTools Regular Expression Denial of Service