Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xr9w-x6gw-c9mj

Опубликовано: 25 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Duplicate advisory: Deno vulnerable to Regular Expression Denial of Service

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-jc97-h3h9-7xh6. This link is maintained to preserve external references.

Original Description

Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server. This issue has been patched in version 1.31.0.

Пакеты

Наименование

deno

rust
Затронутые версииВерсия исправления

< 1.31.0

1.31.0

7.5 High

CVSS3

Дефекты

CWE-1333

7.5 High

CVSS3

Дефекты

CWE-1333