Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-41818

Опубликовано: 28 июл. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.

A regular expression denial of service (ReDoS) flaw was found in fast-xml-parser in the currency.js script. By sending a specially crafted regex input, a remote attacker could cause a denial of service condition.

Отчет

Red Hat has decided to rate this vulnerability as Important due to the potential loss of Availability and the low complexity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 6mta/mta-ui-rhel9Will not fix
Migration Toolkit for Applications 7mta/mta-ui-rhel9Not affected
OpenShift Serverlessfast-xml-parserWill not fix
Red Hat Developer Hubrhdh-operator-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-dashboard-containerAffected
Red Hat OpenShift AI (RHOAI)odh-operator-containerAffected
Red Hat OpenShift Virtualization 4container-native-virtualization/kubevirt-console-pluginAffected
Red Hat Developer Hub 1.2 on RHEL 9rhdh/rhdh-hub-rhel9FixedRHBA-2024:595828.08.2024
RHEL-9-CNV-4.16container-native-virtualization/kubevirt-console-plugin-rhel9FixedRHSA-2024:505406.08.2024
RHODF-4.14-RHEL-9odf4/mcg-core-rhel9FixedRHSA-2024:762403.10.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2300499fast-xml-parser: ReDOS at currency parsing in currency.js

EPSS

Процентиль: 55%
0.00828
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.

CVSS3: 7.5
debian
около 2 лет назад

fast-xml-parser is an open source, pure javascript xml parser. a ReDOS ...

CVSS3: 7.5
github
около 2 лет назад

fast-xml-parser vulnerable to ReDOS at currency parsing

EPSS

Процентиль: 55%
0.00828
Низкий

7.5 High

CVSS3