PT-2024-6620 · Unknown · Find-My-Way

Published

2024-09-18

·

Updated

2024-09-20

·

CVE-2024-45813

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: find-my-way versions prior to 8.2.2 find-my-way versions prior to 9.0.1
Description: The issue is related to the generation of a bad regular expression when two parameters are within a single segment and a - is added at the end, such as /:a-:b-. This may cause a denial of service in some instances. The problem is associated with the use of a regular expression with inefficient computational complexity, which can be exploited by a remote attacker to cause a denial of service.
Recommendations: Update to find-my-way version 8.2.2 or version 9.0.1, or subsequent versions. As a temporary workaround, consider avoiding the use of two parameters within a single segment with a - at the end, such as /:a-:b-, until a patch is available. Restrict access to the vulnerable find-my-way module to minimize the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07779
CVE-2024-45813
GHSA-RRR8-F88R-H8Q6

Affected Products

Find-My-Way