Описание
Denial of Service in foreman
All versions of foreman are vulnerable to Regular Expression Denial of Service when requests to it are made with a specially crafted path.
Recommendation
Upgrade to version 3.0.1.
Пакеты
Наименование
foreman
npm
Затронутые версииВерсия исправления
< 3.0.1
3.0.1
7.5 High
CVSS3
Дефекты
CWE-400
7.5 High
CVSS3
Дефекты
CWE-400