5.3

CVE-2024-4067

Exploit

Regular Expression Denial of Service in micromatch

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JonschlinkertMicromatch SwPlatformnode.js Version < 4.0.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.43% 0.695
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
596c5446-0ce5-4ba2-aa66-48b3b757a647 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-1333 Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

https://advisory.checkmarx.net/advisory/CVE-2024-4067/
Third Party Advisory
Exploit
https://devhub.checkmarx.com/cve-details/CVE-2024-4067/
Third Party Advisory
https://github.com/micromatch/micromatch/commit/03aa8052171e878897eee5d7bb2ae0ae83ec2ade
Patch
https://github.com/micromatch/micromatch/pull/266
Patch
Issue Tracking
https://github.com/micromatch/micromatch/releases/tag/4.0.8
Release Notes
https://github.com/micromatch/micromatch/blob/2c56a8604b68c1099e7bc0f807ce0865a339747a/index.js#L448
Product
https://github.com/micromatch/micromatch/issues/243
Issue Tracking
https://github.com/micromatch/micromatch/pull/247
Patch
Issue Tracking