Логотип exploitDog
bind:CVE-2023-24807
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-24807

Количество 16

Количество 16

ubuntu логотип

CVE-2023-24807

больше 2 лет назад

Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the `headerValueNormalize()` utility function. This vulnerability was patched in v5.19.1. No known workarounds are available.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-24807

больше 2 лет назад

Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the `headerValueNormalize()` utility function. This vulnerability was patched in v5.19.1. No known workarounds are available.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-24807

больше 2 лет назад

Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the `headerValueNormalize()` utility function. This vulnerability was patched in v5.19.1. No known workarounds are available.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-24807

больше 2 лет назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-24807

больше 2 лет назад

Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-r6ch-mqf9-qc9w

больше 2 лет назад

Regular Expression Denial of Service in Headers

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0738-1

больше 2 лет назад

Security update for nodejs18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0715-1

больше 2 лет назад

Security update for nodejs18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0673-1

больше 2 лет назад

Security update for nodejs16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0609-1

больше 2 лет назад

Security update for nodejs16

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0608-1

больше 2 лет назад

Security update for nodejs16

EPSS: Низкий
rocky логотип

RLSA-2023:2655

около 2 лет назад

Moderate: nodejs and nodejs-nodemon security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2023-2655

около 2 лет назад

ELSA-2023-2655: nodejs and nodejs-nodemon security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-1583

больше 2 лет назад

ELSA-2023-1583: nodejs:18 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-2654

около 2 лет назад

ELSA-2023-2654: nodejs:18 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-1582

больше 2 лет назад

ELSA-2023-1582: nodejs:16 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-24807

Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the `headerValueNormalize()` utility function. This vulnerability was patched in v5.19.1. No known workarounds are available.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-24807

Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the `headerValueNormalize()` utility function. This vulnerability was patched in v5.19.1. No known workarounds are available.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-24807

Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the `headerValueNormalize()` utility function. This vulnerability was patched in v5.19.1. No known workarounds are available.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-24807

Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the ...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-r6ch-mqf9-qc9w

Regular Expression Denial of Service in Headers

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0738-1

Security update for nodejs18

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0715-1

Security update for nodejs18

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0673-1

Security update for nodejs16

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0609-1

Security update for nodejs16

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0608-1

Security update for nodejs16

больше 2 лет назад
rocky логотип
RLSA-2023:2655

Moderate: nodejs and nodejs-nodemon security, bug fix, and enhancement update

около 2 лет назад
oracle-oval логотип
ELSA-2023-2655

ELSA-2023-2655: nodejs and nodejs-nodemon security, bug fix, and enhancement update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2023-1583

ELSA-2023-1583: nodejs:18 security, bug fix, and enhancement update (MODERATE)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-2654

ELSA-2023-2654: nodejs:18 security, bug fix, and enhancement update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2023-1582

ELSA-2023-1582: nodejs:16 security, bug fix, and enhancement update (MODERATE)

больше 2 лет назад

Уязвимостей на страницу