PT-2023-19299 · Unknown · Switcher Client

Petruki

·

Publicado

2023-02-02

·

Atualizado

2023-02-15

·

CVE-2023-23925

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Switcher Client versions prior to 3.1.4
Description The issue arises from unsanitized input flowing into the Strategy match operation, specifically the EXIST operation, where it is used to build a regular expression. This can result in a Regular expression Denial of Service attack.
Recommendations For versions prior to 3.1.4, as a temporary workaround, consider avoiding the use of Strategy settings that utilize REGEX in conjunction with EXIST and NOT EXIST operations until a patch is applied. Update to version 3.1.4 to resolve the issue.

Exploit

Correção

Resource Exhaustion

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-23925
GHSA-WQXW-8H5G-HQ56

Produtos afetados

Switcher Client