CVE-2018-7651Uncontrolled Resource Consumption in Project Ssri

Severity
5.9MEDIUMNVD
EPSS
0.4%
top 40.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 4
Latest updateMar 7

Description

index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDssri_project/ssri< 5.2.2
npmssri_project/ssri< 5.2.2

Patches

🔴Vulnerability Details

4
GHSA
Regular Expression Denial of Service in ssri2018-03-07
OSV
Regular Expression Denial of Service in ssri2018-03-07
CVEList
CVE-2018-7651: index2018-03-04
OSV
CVE-2018-7651: index2018-03-04

📋Vendor Advisories

1
Debian
CVE-2018-7651: node-ssri - index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expre...2018

💬Community

2
Bugzilla
CVE-2017-7651 mosquitto: memory exhaustion through multiple crafted CONNECT packets2018-03-05
Bugzilla
CVE-2017-7652 mosquitto: configuration reload fails when no free sockets/file descriptors are available2018-03-05
CVE-2018-7651 — Uncontrolled Resource Consumption | cvebase