Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-7279

Опубликовано: 02 сент. 2024
Источник: nvd
CVSS3: 2.6
CVSS3: 5.9
CVSS2: 1.4
EPSS Низкий

Описание

A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This vulnerability affects unknown code of the file connaisseur/res/targets_schema.json of the component Delegation Name Handler. The manipulation leads to inefficient regular expression complexity. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 3.3.1 is able to address this issue. The name of the patch is 524b73ff7306707f6d3a4d1e86401479bca91b02. It is recommended to upgrade the affected component.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:securesystems:connaisseur:*:*:*:*:*:*:*:*
Версия до 3.3.1 (исключая)

EPSS

Процентиль: 26%
0.00089
Низкий

2.6 Low

CVSS3

5.9 Medium

CVSS3

1.4 Low

CVSS2

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 2.6
github
больше 1 года назад

A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This vulnerability affects unknown code of the file connaisseur/res/targets_schema.json of the component Delegation Name Handler. The manipulation leads to inefficient regular expression complexity. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 3.3.1 is able to address this issue. The name of the patch is 524b73ff7306707f6d3a4d1e86401479bca91b02. It is recommended to upgrade the affected component.

EPSS

Процентиль: 26%
0.00089
Низкий

2.6 Low

CVSS3

5.9 Medium

CVSS3

1.4 Low

CVSS2

Дефекты

CWE-1333