Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qq7-pvm9-x8rf

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

H2O Vulnerable to Denial of Service (DoS) via /3/ParseSetup Endpoint

A vulnerability in the /3/ParseSetup endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexity, leading to the exhaustion of server resources and making the server unresponsive.

Пакеты

Наименование

h2o

pip
Затронутые версииВерсия исправления

>= 3.30.0.7, <= 3.46.0.1

Отсутствует

Наименование

ai.h2o:h2o-core

maven
Затронутые версииВерсия исправления

>= 3.30.0.7, <= 3.46.0.1

Отсутствует

EPSS

Процентиль: 35%
0.00142
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexity, leading to the exhaustion of server resources and making the server unresponsive.

EPSS

Процентиль: 35%
0.00142
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333