PT-2023-24006 · Unknown+1 · Giturlparse+1

Martin Jambon

+1

·

Published

2023-05-15

·

Updated

2025-01-23

·

CVE-2023-32758

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions giturlparse versions through 1.2.2 Semgrep versions 1.5.2 through 1.24.1
Description The issue is related to ReDoS (Regular Expression Denial of Service) when parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package, and that package's author placed a ReDoS attack payload in a URL used by the package.
Recommendations For giturlparse versions through 1.2.2, update to a version that fixes the ReDoS vulnerability. For Semgrep versions 1.5.2 through 1.24.1, update to a version that uses a fixed version of giturlparse. As a temporary workaround, consider restricting the analysis of untrusted packages in Semgrep until a patch is available.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2023-32758
GHSA-4XQQ-73WG-5MJP

Affected Products

Semgrep
Giturlparse