PT-2021-18053 · Unknown · Vfsjfilechooser2

Yetingli

·

Published

2021-06-21

·

Updated

2022-01-06

·

CVE-2021-29061

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Vfsjfilechooser2 versions 0.2.9 and below
Description: A Regular Expression Denial of Service (ReDOS) issue was discovered, occurring when the application attempts to validate crafted URIs.
Recommendations: For Vfsjfilechooser2 versions 0.2.9 and below, consider updating to a version above 0.2.9 to resolve the issue. As a temporary workaround, consider restricting the validation of URIs to minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29061
GHSA-C7FH-CHF7-JR5X

Affected Products

Vfsjfilechooser2