7.5

CVE-2022-25892

Denial of Service (DoS)

The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.02% 0.589
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
report@snyk.io 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/galkahana/HummusJS/issues/463
Third Party Advisory
Issue Tracking
https://github.com/julianhille/MuhammaraJS/commit/1890fb555eaf171db79b73fdc3ea543bbd63c002
Patch
Third Party Advisory
https://github.com/julianhille/MuhammaraJS/commit/90b278d09f16062d93a4160ef0a54d449d739c51
Patch
Third Party Advisory
https://github.com/julianhille/MuhammaraJS/issues/214
Patch
Third Party Advisory
Issue Tracking
https://security.snyk.io/vuln/SNYK-JS-HUMMUS-3091138
Third Party Advisory
https://security.snyk.io/vuln/SNYK-JS-MUHAMMARA-3060320
Third Party Advisory