PT-2021-17385 · Restsharp · Restsharp
Ben Caller
·
Published
2021-07-12
·
Updated
2021-09-09
·
CVE-2021-27293
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
RestSharp versions prior to 106.11.8-alpha.0.13
Description
The issue arises from a vulnerable regular expression used when converting strings into DateTimes, making it susceptible to Regular Expression Denial of Service (ReDoS). If a server responds with a malicious string, the client using the affected software will be stuck processing it for an exceedingly long time, allowing the remote server to trigger a Denial of Service.
Recommendations
For versions prior to 106.11.8-alpha.0.13, update to version 106.11.8-alpha.0.13 or later to resolve the issue. As a temporary workaround, consider restricting the use of the DateTime conversion function to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Restsharp