Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2024-4067

около 2 лет назад

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2024-4067

больше 2 лет назад

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-4067

около 2 лет назад

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2024-4067

около 2 лет назад

EPSS: Низкий
debian логотип

CVE-2024-4067

около 2 лет назад

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular E ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-952p-6rrq-rcjv

около 2 лет назад

Regular Expression Denial of Service (ReDoS) in micromatch

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-09421

больше 2 лет назад

Уязвимость библиотеки micromatch, связанная с неэффективной сложностью регулярных выражений, позволяющая нарушителю получить вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3771-1

почти 2 года назад

Security update for pgadmin4

EPSS: Низкий
redos логотип

ROS-20241029-08

почти 2 года назад

Множественные уязвимости opensearch

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-4067

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
redhat логотип
CVE-2024-4067

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-4067

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.

CVSS3: 5.3
1%
Низкий
около 2 лет назад
msrc логотип
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-4067

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular E ...

CVSS3: 5.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-952p-6rrq-rcjv

Regular Expression Denial of Service (ReDoS) in micromatch

CVSS3: 5.3
1%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-09421

Уязвимость библиотеки micromatch, связанная с неэффективной сложностью регулярных выражений, позволяющая нарушителю получить вызвать отказ в обслуживании

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:3771-1

Security update for pgadmin4

почти 2 года назад
redos логотип
ROS-20241029-08

Множественные уязвимости opensearch

CVSS3: 7.5
почти 2 года назад

Уязвимостей на страницу