7.5
CVE-2022-25887
- EPSS 0.06%
- Veröffentlicht 30.08.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 06:53:09
- Quelle report@snyk.io
- CVE-Watchlists
- Unerledigt
The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apostrophecms ≫ Sanitize-html SwPlatformnode.js Version < 2.7.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.175 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| report@snyk.io | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-1333 Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.