6.5

CVE-2019-16215

The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message causing the server to spend an effectively arbitrary amount of CPU time and stall the processing of future messages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZulipZulip Server Version < 2.0.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.25% 0.655
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-1333 Inefficient Regular Expression Complexity

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

https://blog.zulip.org/2019/09/11/zulip-server-2-0-5-security-release/
Vendor Advisory
https://github.com/zulip/zulip/commit/5797f013b3be450c146a4141514bda525f2f1b51
Patch
Third Party Advisory