PT-2021-18260 · Unknown · Graphhopper
Karussell
·
Published
2021-05-13
·
Updated
2021-05-24
·
CVE-2021-29506
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
GraphHopper versions 2.0 through 2.3
Description:
The issue is related to a regular expression injection that may lead to Denial of Service. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations:
For GraphHopper versions 2.0 through 2.3, update to version 2.4 or 3.0 to resolve the issue.
For versions lower than 2.x with the navigation module added, update to version 2.4 or 3.0 to resolve the issue.
As a temporary workaround, consider disabling the navigation module in versions lower than 2.x until a patch is available.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Graphhopper