Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-9506

Опубликовано: 15 окт. 2024
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.

A flaw was found in Vue.js. Within the parseHTML() function of html-parser.ts, there is a regular expression (regex) to check for proper closing tags for HTML. However, due to an improperly written regex, when you pass a script containing long text, it will trigger a regular expression denial of service (ReDoS) attack, which can cause the process to slow down significantly and render the application unavailable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cldr-emoji-annotationFix deferred
Red Hat Enterprise Linux 7firefoxFix deferred
Red Hat Enterprise Linux 7thunderbirdFix deferred
Red Hat Enterprise Linux 8cldr-emoji-annotationFix deferred
Red Hat Enterprise Linux 8firefoxFix deferred
Red Hat Enterprise Linux 8thunderbirdFix deferred
Red Hat Enterprise Linux 9cldr-emoji-annotationFix deferred
Red Hat Enterprise Linux 9firefoxFix deferred
Red Hat Enterprise Linux 9firefox:flatpak/firefoxFix deferred
Red Hat Enterprise Linux 9gjsFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2318799vue: Regular Expression Denial of Service (ReDoS)

EPSS

Процентиль: 7%
0.00027
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
около 1 года назад

Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.

CVSS3: 3.7
github
около 1 года назад

ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function

EPSS

Процентиль: 7%
0.00027
Низкий

3.1 Low

CVSS3