PT-2023-33000 · Unknown · Http-Cache-Semantics+1
Published
2023-02-11
·
Updated
2023-02-11
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
http-cache-semantics versions prior to 4.1.1
cacheable-request versions prior to 10.2.7
Description
The issue is related to an Inefficient Regular Expression Complexity in http-cache-semantics, which can lead to Denial of Service. This can be exploited via malicious request header values sent to a server when the server reads the cache policy from the request using this library.
Recommendations
For http-cache-semantics versions prior to 4.1.1, update to version 4.1.1 or later.
For cacheable-request versions prior to 10.2.7, update to version 10.2.7 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cacheable-Request
Http-Cache-Semantics