Описание
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.x-1.5 (включая)
Одно из
cpe:2.3:a:drupal:svg_sanitizer:*:*:*:*:*:drupal:*:*
cpe:2.3:a:drupal:svg_sanitizer:8.x-1.0:alpha1:*:*:*:drupal:*:*
EPSS
Процентиль: 59%
0.00384
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-732
Связанные уязвимости
github
больше 3 лет назад
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
EPSS
Процентиль: 59%
0.00384
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-732