Описание
formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.
A flaw was found in the sideway/formula npm package. The formula is a math and string formula parser. In the affected versions of this package, crafted user-provided strings to the formula's parser might lead to polynomial execution time and a denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-ui-rhel8 | Affected | ||
| OpenShift Developer Tools and Services | odo | Will not fix | ||
| Red Hat Data Grid 8 | @sideway-formula | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.
@sideway/formula contains Regular Expression Denial of Service (ReDoS) Vulnerability
EPSS
6.5 Medium
CVSS3