Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-52798

Опубликовано: 05 дек. 2024
Источник: ubuntu
Приоритет: medium

Описание

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296.

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/resolute

not-affected

code not present
esm-apps/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present

Показывать по

РелизСтатусПримечание
devel

not-affected

8.4.0-1
esm-apps-legacy/xenial

not-affected

1.0.1-1
esm-apps/bionic

not-affected

1.0.1-1
esm-apps/focal

not-affected

6.1.0-2
esm-apps/jammy

not-affected

6.2.0-2
esm-apps/noble

not-affected

6.2.1-1
esm-apps/resolute

not-affected

8.4.0-1
esm-apps/xenial

ignored

end of ESM support, was needs-triage
focal

ignored

end of standard support, was needs-triage
jammy

not-affected

6.2.0-2

Показывать по

Связанные уязвимости

CVSS3: 5.3
redhat
больше 1 года назад

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296.

nvd
больше 1 года назад

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296.

msrc
больше 1 года назад

path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x

debian
больше 1 года назад

path-to-regexp turns path strings into a regular expressions. In certa ...

CVSS3: 7.5
github
больше 1 года назад

path-to-regexp contains a ReDoS