PT-2021-18260 · Unknown · Graphhopper

Karussell

·

Published

2021-05-13

·

Updated

2021-05-24

·

CVE-2021-29506

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: GraphHopper versions 2.0 through 2.3
Description: The issue is related to a regular expression injection that may lead to Denial of Service. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations: For GraphHopper versions 2.0 through 2.3, update to version 2.4 or 3.0 to resolve the issue. For versions lower than 2.x with the navigation module added, update to version 2.4 or 3.0 to resolve the issue. As a temporary workaround, consider disabling the navigation module in versions lower than 2.x until a patch is available.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29506
GHSA-HF44-3MX6-VHHW

Affected Products

Graphhopper