Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-3517

Опубликовано: 17 окт. 2022
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-minimatchfixed3.0.5+~3.0.5-1package
node-minimatchfixed3.0.4+~3.0.3-1+deb11u1bullseyepackage

Примечания

  • https://github.com/grafana/grafana-image-renderer/issues/329

  • https://github.com/isaacs/minimatch/commit/a8763f4388e51956be62dc6025cec1126beeb5e6 (v3.0.5)

  • Regression follow-up: https://github.com/isaacs/minimatch/commit/20b4b562830680867feb75f9c635aca08e5c86ff

  • Regression follow-up: https://github.com/isaacs/minimatch/commit/e4cd43462340ca6b21212b68c9e314d8cdd9861a

EPSS

Процентиль: 61%
0.00421
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.

CVSS3: 7.5
redhat
больше 3 лет назад

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.

CVSS3: 7.5
nvd
больше 2 лет назад

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.

CVSS3: 7.5
redos
около 2 лет назад

Уязвимость nodejs-minimatch

CVSS3: 7.5
github
больше 2 лет назад

minimatch ReDoS vulnerability

EPSS

Процентиль: 61%
0.00421
Низкий