PT-2022-23903 · Stealjs · Stealjs

Secdevlpr26

·

Published

2022-09-15

·

Updated

2023-08-08

·

CVE-2022-37262

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions stealjs steal version 2.2.4
Description A Regular Expression Denial of Service (ReDoS) flaw was found in the source and sourceWithComments variables in main.js. This issue can cause a denial of service.
Recommendations For version 2.2.4, consider restricting access to the source and sourceWithComments variables in main.js to minimize the risk of exploitation. Avoid using these variables until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

CVE-2022-37262
GHSA-28V4-JF82-JVJ8

Affected Products

Stealjs