PT-2023-15902 · Sisimai · Sisimai

Gmcabrita

·

Publicado

2023-01-17

·

Atualizado

2024-05-17

·

CVE-2022-4891

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Sisimai versions up to 4.25.14p11
Description A vulnerability has been found in the function to plain of the file lib/sisimai/string.rb, leading to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used.
Recommendations For Sisimai versions up to 4.25.14p11, upgrade to version 4.25.14p12 to address this issue. As a temporary workaround, consider restricting the use of the to plain function in the lib/sisimai/string.rb file until the patch is applied.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-4891
GHSA-VM74-J4WQ-82XJ

Produtos afetados

Sisimai