Логотип exploitDog
bind:CVE-2020-7662
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-7662

Количество 3

Количество 3

redhat логотип

CVE-2020-7662

больше 5 лет назад

websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-7662

больше 5 лет назад

websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g78m-2chm-r7qv

больше 5 лет назад

Regular Expression Denial of Service in websocket-extensions (NPM package)

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-7662

websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-7662

websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-g78m-2chm-r7qv

Regular Expression Denial of Service in websocket-extensions (NPM package)

CVSS3: 8.2
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу