PT-2019-20045 · Braces · Braces
Published
2019-06-06
·
Updated
2019-06-06
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
braces versions prior to 2.3.1
Description
The issue concerns Regular Expression Denial of Service (ReDoS) where untrusted input may cause catastrophic backtracking while matching regular expressions, leading to Denial of Service and causing the application to be unresponsive.
Recommendations
Upgrade to version 2.3.1 or higher.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Braces