PT-2023-10614 · Vercel · Vercel Ms

CVE-2017-20162

·

Publicado

2023-01-05

·

Atualizado

2024-05-17

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions vercel ms versions up to 1.x
Description A problematic issue has been found in the function parse of the file index.js. The manipulation of the argument str leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For vercel ms versions up to 1.x, upgrade to version 2.0.0 to address this issue. As a temporary workaround, consider restricting the use of the parse function in the index.js file until the patch is applied. Restrict access to the str argument to minimize the risk of exploitation.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-43849
AZL-44002
AZL-45126
AZL-45201
CVE-2017-20162
GHSA-W9MR-4MFR-499F

Produtos afetados

Vercel Ms