PT-2022-23902 · Stealjs · Stealjs

Secdevlpr26

·

Published

2022-09-15

·

Updated

2023-08-08

·

CVE-2022-37260

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions stealjs steal version 2.2.4
Description A Regular Expression Denial of Service (ReDoS) flaw was found in the input variable in main.js. This issue can cause a denial of service.
Recommendations For version 2.2.4, consider restricting the input to prevent exploitation of the ReDoS flaw until a patch is available. As a temporary workaround, avoid using the input variable in main.js to minimize the risk of denial of service.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2022-37260
GHSA-7F3X-2WCX-HWW8

Affected Products

Stealjs