PT-2023-19299 · Unknown · Switcher Client
Petruki
·
Publicado
2023-02-02
·
Atualizado
2023-02-15
·
CVE-2023-23925
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Switcher Client versions prior to 3.1.4
Description
The issue arises from unsanitized input flowing into the Strategy match operation, specifically the EXIST operation, where it is used to build a regular expression. This can result in a Regular expression Denial of Service attack.
Recommendations
For versions prior to 3.1.4, as a temporary workaround, consider avoiding the use of Strategy settings that utilize REGEX in conjunction with EXIST and NOT EXIST operations until a patch is applied.
Update to version 3.1.4 to resolve the issue.
Exploit
Correção
Resource Exhaustion
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Switcher Client