PT-2024-15266 · Secure Systems Engineering · Secure Systems Engineering Connaisseur

·

CVE-2023-7279

·

Published

2024-09-02

·

Updated

2024-11-01

CVSS v4.0

2.1

Low

VectorAV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Secure Systems Engineering Connaisseur versions up to 3.3.0
Description A vulnerability has been found in Secure Systems Engineering Connaisseur, affecting unknown code of the file connaisseur/res/targets schema.json of the component Delegation Name Handler. The manipulation leads to inefficient regular expression complexity. The complexity of an attack is rather high, and the exploitation appears to be difficult.
Recommendations To address this issue, upgrade to version 3.3.1. As a temporary workaround, consider restricting access to the vulnerable component Delegation Name Handler until a patch is applied. Ensure the affected component is upgraded to mitigate the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-7279

Affected Products

Secure Systems Engineering Connaisseur