Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9pq7-rcxv-47vq

Опубликовано: 14 июл. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Incorrect Regular Expression in RestSharp

RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp will be stuck processing it for an exceedingly long time. Thus the remote server can trigger Denial of Service.

Пакеты

Наименование

RestSharp

nuget
Затронутые версииВерсия исправления

<= 106.11.7

106.11.8-alpha.0.13

EPSS

Процентиль: 65%
0.00502
Низкий

7.5 High

CVSS3

Дефекты

CWE-185
CWE-697

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp will be stuck processing it for an exceedingly long time. Thus the remote server can trigger Denial of Service.

EPSS

Процентиль: 65%
0.00502
Низкий

7.5 High

CVSS3

Дефекты

CWE-185
CWE-697