PT-2023-10614 · Vercel · Vercel Ms

Published

2023-01-05

·

Updated

2024-05-17

·

CVE-2017-20162

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions vercel ms versions up to 1.x
Description A problematic issue has been found in the function parse of the file index.js. The manipulation of the argument str leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For vercel ms versions up to 1.x, upgrade to version 2.0.0 to address this issue. As a temporary workaround, consider restricting the use of the parse function in the index.js file until the patch is applied. Restrict access to the str argument to minimize the risk of exploitation.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

AZL-43849
AZL-44002
AZL-45126
AZL-45201
CVE-2017-20162
GHSA-W9MR-4MFR-499F

Affected Products

Vercel Ms