7.5

CVE-2023-39619

Exploit
ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpSyntax component.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TeomantuncerNode Email Check Version1.0.4 SwPlatformnode.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.08% 0.606
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-1333 Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

https://gist.github.com/6en6ar/712a4c1eab0324f15e09232c77ea08f8
Exploit
https://github.com/teomantuncer/node-email-check/blob/main/main.js%2C
https://www.npmjs.com/package/node-email-check
Product