PT-2024-6620 · Unknown · Find-My-Way
Published
2024-09-18
·
Updated
2024-09-20
·
CVE-2024-45813
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
find-my-way versions prior to 8.2.2
find-my-way versions prior to 9.0.1
Description:
The issue is related to the generation of a bad regular expression when two parameters are within a single segment and a
- is added at the end, such as /:a-:b-. This may cause a denial of service in some instances. The problem is associated with the use of a regular expression with inefficient computational complexity, which can be exploited by a remote attacker to cause a denial of service.Recommendations:
Update to find-my-way version 8.2.2 or version 9.0.1, or subsequent versions.
As a temporary workaround, consider avoiding the use of two parameters within a single segment with a
- at the end, such as /:a-:b-, until a patch is available.
Restrict access to the vulnerable find-my-way module to minimize the risk of exploitation.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Find-My-Way