Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jc97-h3h9-7xh6

Опубликовано: 03 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Regular Expression Denial of Service in Deno.upgradeWebSocket API

Impact

Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server.

Patches

It is recommended that users upgrade to Deno 1.31.0.

Пакеты

Наименование

deno

rust
Затронутые версииВерсия исправления

>= 1.12.0, < 1.31.0

1.31.0

EPSS

Процентиль: 32%
0.00123
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 5.3
nvd
почти 3 года назад

Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server.

EPSS

Процентиль: 32%
0.00123
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1333