Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4xqq-73wg-5mjp

Опубликовано: 15 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

git-url-parse Regular Expression Denial of Service

giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an http:// URL), and that package's author placed a ReDoS attack payload in a URL used by the package.

Пакеты

Наименование

git-url-parse

pip
Затронутые версииВерсия исправления

<= 1.2.2

Отсутствует

EPSS

Процентиль: 41%
0.00195
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an http:// URL), and that package's author placed a ReDoS attack payload in a URL used by the package.

EPSS

Процентиль: 41%
0.00195
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333