7.5

CVE-2022-25858

Exploit

Regular Expression Denial of Service (ReDoS)

Terser < 4.8.1 and 5.0.0-5.14.1 - Regular Expression Denial of Service

terser (JS Package) < 5.14.2 - Denial of Service

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
Mögliche Gegenmaßnahme
Autopost for X (formerly Autoshare for Twitter): Update to version 1.2.0, or a newer patched version
Block for Apple Maps: Update to version 1.1.0, or a newer patched version
Publisher Media Kit: Update to version 1.3.0, or a newer patched version
Retro Winamp Block: Update to version 1.2.0, or a newer patched version
ElasticPress: Update to version 4.3.0, or a newer patched version
Retro Winamp Block: Update to version 1.2.0, or a newer patched version
Simple Local Avatars: Update to version 2.6.0, or a newer patched version
Simple Podcasting: Update to version 1.2.4, or a newer patched version
Sophi: Update to version 1.2.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TerserTerser SwPlatformnode.js Version < 4.8.1
TerserTerser SwPlatformnode.js Version >= 5.0.0 < 5.14.2
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Autopost for X (formerly Autoshare for Twitter)
Version *-1.1.2
SystemWordPress Plugin
Produkt Block for Apple Maps
Version *-1.0.3
SystemWordPress Plugin
Produkt Publisher Media Kit
Version *-1.2.1
SystemWordPress Plugin
Produkt Retro Winamp Block
Version *-1.1.0
SystemWordPress Plugin
Produkt ElasticPress
Version *-4.2.2
SystemWordPress Plugin
Produkt Retro Winamp Block
Version *-1.1.0
SystemWordPress Plugin
Produkt Simple Local Avatars
Version *-2.5.0
SystemWordPress Plugin
Produkt Simple Podcasting
Version [*, 1.2.4)
SystemWordPress Plugin
Produkt Sophi
Version *-1.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.32% 0.812
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
report@snyk.io 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-1333 Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

https://github.com/terser/terser/blob/master/lib/compress/evaluate.js%23L135
Broken Link
https://github.com/terser/terser/commit/a4da7349fdc92c05094f41d33d06d8cd4e90e76b
Patch
Third Party Advisory
https://github.com/terser/terser/commit/d8cc5691be980d663c29cc4d5ce67e852d597012
Patch
Third Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2949722
Patch
Third Party Advisory
Exploit
https://snyk.io/vuln/SNYK-JS-TERSER-2806366
Patch
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/d535c069-cfa3-4c41-9a01-b4c4e7c75764
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/f1c08c10-7358-4618-b892-7d222ba460de
Third Party Advisory