Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v63q-hgqc-qvpg

Опубликовано: 03 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

MooTools Regular Expression Denial of Service

MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.

Пакеты

Наименование

mootools

npm
Затронутые версииВерсия исправления

<= 1.5.2

Отсутствует

EPSS

Процентиль: 42%
0.00196
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-400

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 3 лет назад

MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.

CVSS3: 6.2
nvd
около 3 лет назад

MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.

CVSS3: 6.2
debian
около 3 лет назад

MooTools is a collection of JavaScript utilities for JavaScript develo ...

EPSS

Процентиль: 42%
0.00196
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-400