Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-45813

Опубликовано: 18 сент. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a single segment, when adding a - at the end, like /:a-:b-. This may cause a denial of service in some instances. Users are advised to update to find-my-way v8.2.2 or v9.0.1. or subsequent versions. There are no known workarounds for this issue.

A regular expression denial of service (ReDoS) flaw was found in find-my-way. A bad regular expression is generated any time one has two parameters within a single segment, when adding a - at the end, such as /:a-:b-. This issue may cause a denial of service in some instances.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)odh-dashboard-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-operator-containerNot affected
Red Hat OpenShift Data Science (RHODS)rhods/odh-dashboard-rhel8Will not fix
Red Hat OpenShift Data Science (RHODS)rhods/odh-operator-rhel8Not affected
Red Hat OpenShift Data Science (RHODS)rhods/odh-rhel8-operatorNot affected
multicluster engine for Kubernetes 2.6 for RHEL 8multicluster-engine/assisted-image-service-rhel8FixedRHSA-2024:1129317.12.2024
multicluster engine for Kubernetes 2.6 for RHEL 8multicluster-engine/assisted-installer-agent-rhel8FixedRHSA-2024:1129317.12.2024
multicluster engine for Kubernetes 2.6 for RHEL 8multicluster-engine/assisted-installer-controller-rhel8FixedRHSA-2024:1129317.12.2024
multicluster engine for Kubernetes 2.6 for RHEL 8multicluster-engine/assisted-installer-rhel8FixedRHSA-2024:1129317.12.2024
multicluster engine for Kubernetes 2.6 for RHEL 8multicluster-engine/assisted-service-8-rhel8FixedRHSA-2024:1129317.12.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2313383find-my-way: ReDoS vulnerability in multiparametric routes

EPSS

Процентиль: 15%
0.00048
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. A bad regular expression is generated any time one has two parameters within a single segment, when adding a `-` at the end, like `/:a-:b-`. This may cause a denial of service in some instances. Users are advised to update to find-my-way v8.2.2 or v9.0.1. or subsequent versions. There are no known workarounds for this issue.

CVSS3: 7.5
github
больше 1 года назад

find-my-way has a ReDoS vulnerability in multiparametric routes

CVSS3: 5.3
fstec
больше 1 года назад

Уязвимость HTTP-маршрутизатора Find my Way, связанная с использованием регулярного выражения c неэффективной вычислительной сложностью, позволяющая нарушителю вызвать отказ в обслуживании (ReDos)

EPSS

Процентиль: 15%
0.00048
Низкий

7.5 High

CVSS3