Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-25166

Опубликовано: 08 фев. 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.

A flaw was found in the sideway/formula npm package. The formula is a math and string formula parser. In the affected versions of this package, crafted user-provided strings to the formula's parser might lead to polynomial execution time and a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Affected
OpenShift Developer Tools and ServicesodoWill not fix
Red Hat Data Grid 8@sideway-formulaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2168451@sideway/formula: Regular Expression Denial of Service (ReDoS) Vulnerability

EPSS

Процентиль: 78%
0.01086
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
почти 3 года назад

formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.

CVSS3: 5.5
github
почти 3 года назад

@sideway/formula contains Regular Expression Denial of Service (ReDoS) Vulnerability

EPSS

Процентиль: 78%
0.01086
Низкий

6.5 Medium

CVSS3