PT-2023-24006 · Unknown+1 · Giturlparse+1
Martin Jambon
+1
·
Published
2023-05-15
·
Updated
2025-01-23
·
CVE-2023-32758
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
giturlparse versions through 1.2.2
Semgrep versions 1.5.2 through 1.24.1
Description
The issue is related to ReDoS (Regular Expression Denial of Service) when parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package, and that package's author placed a ReDoS attack payload in a URL used by the package.
Recommendations
For giturlparse versions through 1.2.2, update to a version that fixes the ReDoS vulnerability.
For Semgrep versions 1.5.2 through 1.24.1, update to a version that uses a fixed version of giturlparse.
As a temporary workaround, consider restricting the analysis of untrusted packages in Semgrep until a patch is available.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Semgrep
Giturlparse