PT-2023-33000 · Unknown · Http-Cache-Semantics+1

Published

2023-02-11

·

Updated

2023-02-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions http-cache-semantics versions prior to 4.1.1 cacheable-request versions prior to 10.2.7
Description The issue is related to an Inefficient Regular Expression Complexity in http-cache-semantics, which can lead to Denial of Service. This can be exploited via malicious request header values sent to a server when the server reads the cache policy from the request using this library.
Recommendations For http-cache-semantics versions prior to 4.1.1, update to version 4.1.1 or later. For cacheable-request versions prior to 10.2.7, update to version 10.2.7 or later.

Fix

DoS

Weakness Enumeration

Related Identifiers

GHSA-8X6C-CV3V-VP6G

Affected Products

Cacheable-Request
Http-Cache-Semantics