PT-2022-23902 · Stealjs · Stealjs

·

CVE-2022-37260

·

Published

2022-09-15

·

Updated

2023-08-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions stealjs steal version 2.2.4
Description A Regular Expression Denial of Service (ReDoS) flaw was found in the input variable in main.js. This issue can cause a denial of service.
Recommendations For version 2.2.4, consider restricting the input to prevent exploitation of the ReDoS flaw until a patch is available. As a temporary workaround, avoid using the input variable in main.js to minimize the risk of denial of service.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-37260
GHSA-7F3X-2WCX-HWW8

Affected Products

Stealjs