Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cp3-fh5x-xfcj

Опубликовано: 09 авг. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Regular Expression Denial of Service in charset

Affected versions of charset are susceptible to a regular expression denial of service.

The amplification on this vulnerability is relatively low - it takes around 2 seconds for the engine to execute on a malicious input which is 50,000 characters in length.

If node was compiled using the -DHTTP_MAX_HEADER_SIZE however, the impact of the vulnerability can be significant, as the primary limitation for the vulnerability is the default max HTTP header length in node.

Recommendation

Update to version 1.0.1 or later.

Пакеты

Наименование

charset

npm
Затронутые версииВерсия исправления

< 1.0.1

1.0.1

EPSS

Процентиль: 55%
0.00328
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low.

EPSS

Процентиль: 55%
0.00328
Низкий

7.5 High

CVSS3

Дефекты

CWE-400