Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hf44-3mx6-vhhw

Опубликовано: 19 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Navigate endpoint is vulnerable to regex injection that may lead to Denial of Service.

Impact

The regex injection that may lead to Denial of Service.

Patches

Will be patched in 2.4 and 3.0

Workarounds

Versions lower than 2.x are only affected if the navigation module is added

References

See this pull request for the fix: https://github.com/graphhopper/graphhopper/pull/2304

If you have any questions or comments about this advisory please send us an Email or create a topic here.

Пакеты

Наименование

com.graphhopper:graphhopper-nav

maven
Затронутые версииВерсия исправления

< 2.4

2.4

EPSS

Процентиль: 59%
0.00376
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
nvd
больше 4 лет назад

GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vulnerability that may lead to Denial of Service. This has been patched in 2.4 and 3.0 See this pull request for the fix: https://github.com/graphhopper/graphhopper/pull/2304

EPSS

Процентиль: 59%
0.00376
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400