PT-2023-12409 · Unknown · Woorank Robots-Txt-Guard

Published

2023-01-05

·

Updated

2024-05-17

·

CVE-2021-4305

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Woorank robots-txt-guard (affected versions not specified)
Description A vulnerability was found in the function makePathPattern of the file lib/patterns.js. The manipulation of the argument pattern leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used.
Recommendations Apply a patch to fix this issue, specifically the patch c03827cd2f9933619c23894ce7c98401ea824020. As a temporary workaround, consider restricting the use of the makePathPattern function until a patch is available.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2021-4305
GHSA-6G33-8W2Q-4HXV

Affected Products

Woorank Robots-Txt-Guard