Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-39fp-mqmm-gxj6

Опубликовано: 29 мар. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

CodeIgniter4 DoS Vulnerability

Impact

A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server.

Patches

Upgrade to v4.4.7 or later. See upgrading guide.

Workarounds

  • Disabling Auto Routing prevents a known attack vector in the framework.
  • Do not pass invalid values to the lang() function or Language class.

References

Пакеты

Наименование

codeigniter4/framework

composer
Затронутые версииВерсия исправления

< 4.4.7

4.4.7

EPSS

Процентиль: 68%
0.00569
Низкий

7.5 High

CVSS3

Дефекты

CWE-674
CWE-835

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server. Upgrade to v4.4.7 or later.

CVSS3: 7.5
debian
почти 2 года назад

CodeIgniter is a PHP full-stack web framework A vulnerability was foun ...

EPSS

Процентиль: 68%
0.00569
Низкий

7.5 High

CVSS3

Дефекты

CWE-674
CWE-835