PT-2022-11821 · Npm · Uri-Template-Lite

·

CVE-2021-43309

·

Published

2022-08-24

·

Updated

2023-07-18

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions uri-template-lite npm package (affected versions not specified)
Description An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package when an attacker is able to supply arbitrary input to the URI.expand method. This issue allows an attacker to cause a denial of service by exploiting the regular expression engine.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the input to the URI.expand method to prevent arbitrary input from being processed.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43309
GHSA-CHW2-6C7R-37P7

Affected Products

Uri-Template-Lite