PT-2023-19299 · Unknown · Switcher Client

Petruki

·

Published

2023-02-02

·

Updated

2023-02-15

·

CVE-2023-23925

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Switcher Client versions prior to 3.1.4
Description The issue arises from unsanitized input flowing into the Strategy match operation, specifically the EXIST operation, where it is used to build a regular expression. This can result in a Regular expression Denial of Service attack.
Recommendations For versions prior to 3.1.4, as a temporary workaround, consider avoiding the use of Strategy settings that utilize REGEX in conjunction with EXIST and NOT EXIST operations until a patch is applied. Update to version 3.1.4 to resolve the issue.

Exploit

Fix

Resource Exhaustion

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-23925
GHSA-WQXW-8H5G-HQ56

Affected Products

Switcher Client