Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-23925

Опубликовано: 03 фев. 2023
Источник: nvd
CVSS3: 8.6
CVSS3: 7.5
EPSS Низкий

Описание

Switcher Client is a JavaScript SDK to work with Switcher API which is cloud-based Feature Flag. Unsanitized input flows into Strategy match operation (EXIST), where it is used to build a regular expression. This may result in a Regular expression Denial of Service attack (reDOS). This issue has been patched in version 3.1.4. As a workaround, avoid using Strategy settings that use REGEX in conjunction with EXIST and NOT_EXIST operations.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:switcherapi:switcher_client:*:*:*:*:*:node.js:*:*
Версия до 3.1.4 (исключая)

EPSS

Процентиль: 63%
0.00446
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-400
CWE-1333

Связанные уязвимости

CVSS3: 7.5
github
около 3 лет назад

Switcher Client contains Regular Expression Denial of Service (ReDoS)

EPSS

Процентиль: 63%
0.00446
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-400
CWE-1333