PT-2021-18053 · Unknown · Vfsjfilechooser2
Yetingli
·
Published
2021-06-21
·
Updated
2022-01-06
·
CVE-2021-29061
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Vfsjfilechooser2 versions 0.2.9 and below
Description:
A Regular Expression Denial of Service (ReDOS) issue was discovered, occurring when the application attempts to validate crafted URIs.
Recommendations:
For Vfsjfilechooser2 versions 0.2.9 and below, consider updating to a version above 0.2.9 to resolve the issue.
As a temporary workaround, consider restricting the validation of URIs to minimize the risk of exploitation.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vfsjfilechooser2