Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-41818

Опубликовано: 28 июл. 2024
Источник: redhat
CVSS3: 7.5

Описание

fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.

A regular expression denial of service (ReDoS) flaw was found in fast-xml-parser in the currency.js script. By sending a specially crafted regex input, a remote attacker could cause a denial of service condition.

Отчет

Red Hat has decided to rate this vulnerability as Important due to the potential loss of Availability and the low complexity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 6mta/mta-ui-rhel9Will not fix
Migration Toolkit for Applications 7mta/mta-ui-rhel9Not affected
OpenShift Serverlessfast-xml-parserWill not fix
Red Hat Developer Hubrhdh-operator-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-dashboard-containerAffected
Red Hat OpenShift AI (RHOAI)odh-operator-containerAffected
Red Hat OpenShift Virtualization 4container-native-virtualization/kubevirt-console-pluginAffected
Red Hat Developer Hub 1.2 on RHEL 9rhdh/rhdh-hub-rhel9FixedRHBA-2024:595828.08.2024
RHEL-9-CNV-4.16container-native-virtualization/kubevirt-console-plugin-rhel9FixedRHSA-2024:505406.08.2024
RHODF-4.14-RHEL-9odf4/mcg-core-rhel9FixedRHSA-2024:762403.10.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2300499fast-xml-parser: ReDOS at currency parsing in currency.js

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.

CVSS3: 7.5
debian
больше 1 года назад

fast-xml-parser is an open source, pure javascript xml parser. a ReDOS ...

CVSS3: 7.5
github
больше 1 года назад

fast-xml-parser vulnerable to ReDOS at currency parsing

7.5 High

CVSS3