Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2jc-4fpr-4vhg

Опубликовано: 08 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

@sideway/formula contains Regular Expression Denial of Service (ReDoS) Vulnerability

Impact

User-provided strings to formula's parser might lead to polynomial execution time.

Patches

Users should upgrade to 3.0.1+.

Workarounds

None.

Пакеты

Наименование

@sideway/formula

npm
Затронутые версииВерсия исправления

< 3.0.1

3.0.1

EPSS

Процентиль: 78%
0.01086
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 6.5
redhat
почти 3 года назад

formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.

CVSS3: 5.5
nvd
почти 3 года назад

formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 78%
0.01086
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-1333