PT-2022-23900 · Stealjs · Stealjs

Secdevlpr26

·

Published

2022-09-20

·

Updated

2023-08-08

·

CVE-2022-37259

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions stealjs steal version 2.2.4
Description A Regular Expression Denial of Service (ReDoS) flaw was found in the software via the string variable in babel.js. This issue can cause a denial of service.
Recommendations For version 2.2.4, consider restricting access to the babel.js file or disabling the use of the string variable until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2022-37259
GHSA-RGQX-226F-2XP4

Affected Products

Stealjs