7.5
CVE-2022-25858
- EPSS 2.32%
- Veröffentlicht 15.07.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:07
- Quelle report@snyk.io
- CVE-Watchlists
- Unerledigt
Regular Expression Denial of Service (ReDoS)
Terser < 4.8.1 and 5.0.0-5.14.1 - Regular Expression Denial of Service
terser (JS Package) < 5.14.2 - Denial of Service
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
Mögliche Gegenmaßnahme
Autopost for X (formerly Autoshare for Twitter): Update to version 1.2.0, or a newer patched version
Block for Apple Maps: Update to version 1.1.0, or a newer patched version
Publisher Media Kit: Update to version 1.3.0, or a newer patched version
Retro Winamp Block: Update to version 1.2.0, or a newer patched version
ElasticPress: Update to version 4.3.0, or a newer patched version
Retro Winamp Block: Update to version 1.2.0, or a newer patched version
Simple Local Avatars: Update to version 2.6.0, or a newer patched version
Simple Podcasting: Update to version 1.2.4, or a newer patched version
Sophi: Update to version 1.2.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Autopost for X (formerly Autoshare for Twitter)
Version
*-1.1.2
SystemWordPress Plugin
≫
Produkt
Block for Apple Maps
Version
*-1.0.3
SystemWordPress Plugin
≫
Produkt
Publisher Media Kit
Version
*-1.2.1
SystemWordPress Plugin
≫
Produkt
Retro Winamp Block
Version
*-1.1.0
SystemWordPress Plugin
≫
Produkt
ElasticPress
Version
*-4.2.2
SystemWordPress Plugin
≫
Produkt
Retro Winamp Block
Version
*-1.1.0
SystemWordPress Plugin
≫
Produkt
Simple Local Avatars
Version
*-2.5.0
SystemWordPress Plugin
≫
Produkt
Simple Podcasting
Version
[*, 1.2.4)
SystemWordPress Plugin
≫
Produkt
Sophi
Version
*-1.2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.32% | 0.812 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| report@snyk.io | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-1333 Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
https://github.com/terser/terser/blob/master/lib/compress/evaluate.js%23L135
https://github.com/terser/terser/commit/a4da7349fdc92c05094f41d33d06d8cd4e90e76b
https://github.com/terser/terser/commit/d8cc5691be980d663c29cc4d5ce67e852d597012
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2949722
https://snyk.io/vuln/SNYK-JS-TERSER-2806366
https://www.wordfence.com/threat-intel/vulnerabilities/id/d535c069-cfa3-4c41-9a01-b4c4e7c75764
https://www.wordfence.com/threat-intel/vulnerabilities/id/f1c08c10-7358-4618-b892-7d222ba460de