Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25881

Опубликовано: 31 янв. 2023
Источник: redhat
CVSS3: 7.5

Описание

This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

A flaw was found in http-cache-semantics. When the server reads the cache policy from the request using this library, a Regular Expression Denial of Service occurs, caused by malicious request header values sent to the server.

Отчет

The impact of a succesfull exploiation of this vulnerability will only lead to a denial of service of the system,furthermore the exploitation will require an attacker to specifically craft a regular expression patterns in request headers (i.e. nontrivial input) that trigger pathological regex behavior but since most systems will have limits on header sizes or input validation that reduce the risk of triggering the extreme pathological regex cases which is why this has been marked as moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Affected
.NET 6.0 on Red Hat Enterprise Linuxrh-dotnet60-dotnetOut of support scope
OpenShift Service Mesh 2openshift-service-mesh/kiali-rhel8Affected
OpenShift Service Mesh 2.1openshift-service-mesh/kiali-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-api-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-central-db-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-docs-rhel8Will not fix
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Will not fix
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-rhel8-operatorWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2165824http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

CVSS3: 7.5
msrc
около 1 месяца назад

This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server when that server reads the cache policy from the request using this library.

suse-cvrf
почти 3 года назад

Security update for nodejs16

suse-cvrf
почти 3 года назад

Security update for nodejs16

suse-cvrf
почти 3 года назад

Security update for nodejs16

7.5 High

CVSS3