7.5
CVE-2020-36661
- EPSS 0.92%
- Veröffentlicht 12.02.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:30:02
- Quelle cna@vuldb.com
- CVE-Watchlists
- Unerledigt
Kong lua-multipart multipart.lua is_header redos
A vulnerability was found in Kong lua-multipart 0.5.8-1. It has been declared as problematic. This vulnerability affects the function is_header of the file src/multipart.lua. The manipulation leads to inefficient regular expression complexity. Upgrading to version 0.5.9-1 is able to address this issue. The patch is identified as d632e5df43a2928fd537784a99a79dec288bf01b. It is recommended to upgrade the affected component. VDB-220642 is the identifier assigned to this vulnerability.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.92% | 0.556 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| cna@vuldb.com | 3.5 | 2.1 | 1.4 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
|
| cna@vuldb.com | 2.7 | 5.1 | 2.9 |
AV:A/AC:L/Au:S/C:N/I:N/A:P
|
CWE-1333 Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
https://github.com/Kong/lua-multipart/commit/d632e5df43a2928fd537784a99a79dec288bf01b
https://github.com/Kong/lua-multipart/pull/34
https://github.com/Kong/lua-multipart/releases/tag/0.5.9-1
https://vuldb.com/?ctiid.220642
https://vuldb.com/?id.220642