Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-26115

Опубликовано: 22 июн. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.

A flaw was found in the Node.js word-wrap module, where it is vulnerable to a denial of service caused by a Regular expression denial of service (ReDoS) issue in the result variable. By sending a specially crafted regex input, a remote attacker can cause a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Interconnect 1word-wrapNot affected
Cryostat 2word-wrapNot affected
Migration Toolkit for Applications 6mta/mta-ui-rhel9Affected
Migration Toolkit for Runtimesorg.jboss.windup-windup-parentNot affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Will not fix
OpenShift Service Mesh 2openshift-service-mesh/kiali-rhel8Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2acm-cluster-templates-console-plugin-containerWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-api-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1333

EPSS

Процентиль: 4%
0.0002
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.

CVSS3: 5.3
github
около 2 лет назад

word-wrap vulnerable to Regular Expression Denial of Service

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость модуля word-wrap программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 4%
0.0002
Низкий

7.5 High

CVSS3