Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-25844

Опубликовано: 01 мая 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 5.3

Описание

The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. Note: 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.

РелизСтатусПримечание
bionic

not-affected

1.5.10-1
devel

not-affected

1.8.3-3
esm-apps/focal

released

1.7.9-1ubuntu0.1~esm1
esm-apps/jammy

released

1.8.2-2ubuntu0.1
esm-apps/noble

released

1.8.3-1ubuntu0.24.04.1
esm-infra/bionic

not-affected

1.5.10-1
esm-infra/xenial

not-affected

1.2.28-1ubuntu2
focal

ignored

end of standard support, was needed
impish

ignored

end of life
jammy

released

1.8.2-2ubuntu0.1

Показывать по

EPSS

Процентиль: 83%
0.01924
Низкий

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 4 года назад

The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.

CVSS3: 5.3
nvd
почти 4 года назад

The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.

CVSS3: 5.3
debian
почти 4 года назад

The package angular after 1.7.0 are vulnerable to Regular Expression D ...

CVSS3: 5.3
github
почти 4 года назад

angular vulnerable to regular expression denial of service (ReDoS)

CVSS3: 7.5
fstec
почти 4 года назад

Уязвимость службы $resource среды проектирования приложений и платформы разработки одностраничных приложений Аngular, связанная с использованием регулярного выражения c неэффективной вычислительной сложностью, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 83%
0.01924
Низкий

5 Medium

CVSS2

5.3 Medium

CVSS3