7.5

CVE-2022-24373

Exploit

Regular Expression Denial of Service (ReDoS)

The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper usage of regular expression in the parser of Colors.js.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SwmansionReact Native Reanimated Version < 2.10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.22% 0.648
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
report@snyk.io 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-1333 Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

https://github.com/software-mansion/react-native-reanimated/pull/3382
Patch
Third Party Advisory
Exploit
https://github.com/software-mansion/react-native-reanimated/pull/3382/commits/7adf06d0c59382d884a04be86a96eede3d0432fa
Patch
Third Party Advisory
https://github.com/software-mansion/react-native-reanimated/releases/tag/3.0.0-rc.1
Patch
Third Party Advisory
Release Notes
https://security.snyk.io/vuln/SNYK-JS-REACTNATIVEREANIMATED-2949507
Patch
Third Party Advisory
Exploit