CVE-2020-1333
published 2020-07-14CVE-2020-1333: An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy…
PriorityP426medium6.7CVSS 3.1
AVLACHPRLUIRSUCHIHAH
EPSS
0.92%
56.6th percentile
An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'.
Affected
81 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansman | validate.js | 0 – 0.13.1 | — |
| bevacqua | insane | 0 – 2.6.2 | — |
| foundation | foundation-sites | 0 – 6.3.3 | — |
| ftonato | nope-validator | >= 0 < 0.12.1 | 0.12.1 |
| leoeditor | leo | >= 0 < 6.3 | 6.3 |
| lodash | lodash | >= 4.0.0 < 4.17.21 | 4.17.21 |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
vendor_redhat8.7HIGH
vendor_msrc6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
insane: GHSL-2020-289: Regular Expression Denial of Service (ReDoS) in insane
vendor_redhat·2024-10-26·CVSS 8.7
CVE-2020-26303 [HIGH] CWE-1333 insane: GHSL-2020-289: Regular Expression Denial of Service (ReDoS) in insane
insane: GHSL-2020-289: Regular Expression Denial of Service (ReDoS) in insane
insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
A flaw was found in the insane package, a whitelist-oriented HTML sanitizer. Affected versions of this package contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS).
Statement: The ReDoS vulnerability in insane is categorized as an important severity issue rather than critical due to the specific conditions required for exploitation and the nature of the impact. ReDoS attacks exploit inefficient regular expressions that c
Red Hat
Useragent: GHSL-2020-312: Regular Expression Denial of Service (ReDoS) in useragent
vendor_redhat·2024-10-26·CVSS 8.7
CVE-2020-26311 [HIGH] CWE-1333 Useragent: GHSL-2020-312: Regular Expression Denial of Service (ReDoS) in useragent
Useragent: GHSL-2020-312: Regular Expression Denial of Service (ReDoS) in useragent
Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no patches are available.
A flaw was found in Useragent package, a user agent parser for Node.js. Affected versions of this package contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS).
Statement: The ReDoS vulnerability in the useragent library is considered an important severity rather than critical because it primarily affects application availability, not confidentiality or integrity. This vulnerability occurs when inefficient re
Red Hat
papaparse: RegExp used to detect numbers is vulnerable to ReDoS
vendor_redhat·2023-01-11·CVSS 3.5
CVE-2020-36649 [LOW] CWE-1333 papaparse: RegExp used to detect numbers is vulnerable to ReDoS
papaparse: RegExp used to detect numbers is vulnerable to ReDoS
A vulnerability was found in mholt PapaParse up to 5.1.x. It has been classified as problematic. Affected is an unknown function of the file papaparse.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 5.2.0 is able to address this issue. The name of the patch is 235a12758cd77266d2e98fd715f53536b34ad621. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218004.
A vulnerability was found in PapaParse. The affected function is present in the papaparse.js file. The manipulation leads to an inefficient regular expression complexity.
Package: servicemesh-grafana (OpenShift Service Mesh 2.1) - Not affected
Package: grafana (Red Hat Enterpri
Red Hat
python-jinja2: ReDoS vulnerability in the urlize filter
vendor_redhat·2021-02-01·CVSS 5.3
CVE-2020-28493 [MEDIUM] CWE-1333 python-jinja2: ReDoS vulnerability in the urlize filter
python-jinja2: ReDoS vulnerability in the urlize filter
This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.
A flaw was found in python-jinja2. The ReDOS vulnerability of the regex is mainly due to the sub-pattern [a-zA-Z0-9._-]+.[a-zA-Z0-9._-]+. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.
Statement: This flaw is out o
Microsoft
Group Policy Services Policy Processing Elevation of Privilege Vulnerability
vendor_msrc·2020-07-14·CVSS 6.7
CVE-2020-1333 [MEDIUM] Group Policy Services Policy Processing Elevation of Privilege Vulnerability
Group Policy Services Policy Processing Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points. An attacker who successfully exploited this vulnerability could overwrite a targeted file that would normally require elevated permissions.
To exploit the vulnerability, an attacker would first have to log on to a system and create folders that will be used by Group Policy logging and tracing. The attacker could then run a specially crafted application to target a file for overwriting, and then wait for the administrator to apply the Group Policy logging and tracing settings on the vulnerable system.
The security update addresses the vulnerability by correcting how Group Polic
Red Hat
OpenJDK: Regular expression DoS in Scanner (Concurrency, 8236201)
vendor_redhat·2020-04-14·CVSS 5.3
CVE-2020-2830 [MEDIUM] CWE-1333 OpenJDK: Regular expression DoS in Scanner (Concurrency, 8236201)
OpenJDK: Regular expression DoS in Scanner (Concurrency, 8236201)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the s
GHSA
nope-validator Regular Expression Denial of Service vulnerability
ghsa·2024-10-26
CVE-2020-26309 [MEDIUM] CWE-1333 nope-validator Regular Expression Denial of Service vulnerability
nope-validator Regular Expression Denial of Service vulnerability
Nope is a JavaScript validator. Versions 0.11.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). This vulnerability is fixed in 0.12.1.
GHSA
Knwl.js Regular Expression Denial of Service vulnerability
ghsa·2024-10-26
CVE-2020-26306 [MEDIUM] CWE-1333 Knwl.js Regular Expression Denial of Service vulnerability
Knwl.js Regular Expression Denial of Service vulnerability
Knwl.js is a Javascript library that parses through text for dates, times, phone numbers, emails, places, and more. Versions 1.0.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
GHSA
validate.js Regular Expression Denial of Service vulnerability
ghsa·2024-10-26
CVE-2020-26308 [MEDIUM] CWE-1333 validate.js Regular Expression Denial of Service vulnerability
validate.js Regular Expression Denial of Service vulnerability
Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
GHSA
insane vulnerable to Regular Expression Denial of Service
ghsa·2024-10-26
CVE-2020-26303 [MEDIUM] CWE-1333 insane vulnerable to Regular Expression Denial of Service
insane vulnerable to Regular Expression Denial of Service
insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
GHSA
CommonRegexJS Regular Expression Denial of Service vulnerability
ghsa·2024-10-26
CVE-2020-26305 [MEDIUM] CWE-1333 CommonRegexJS Regular Expression Denial of Service vulnerability
CommonRegexJS Regular Expression Denial of Service vulnerability
CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
GHSA
useragent Regular Expression Denial of Service vulnerability
ghsa·2024-10-26
CVE-2020-26311 [MEDIUM] CWE-1333 useragent Regular Expression Denial of Service vulnerability
useragent Regular Expression Denial of Service vulnerability
Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS).
## PoC
```js
async function exploit() {
const useragent = require(\"useragent\");
// Create a malicious user-agent that leads to excessive backtracking
const maliciousUserAgent = 'Mozilla/5.0 (' + 'X'.repeat(30000) + ') Gecko/20100101 Firefox/77.0';
// Parse the malicious user-agent
const agent = useragent.parse(maliciousUserAgent);
// Call the toString method to trigger the vulnerability
const result = await agent.device.toString();
console.log(result);
}
await exploit();
```
GHSA
Foundation Regular Expression Denial of Service vulnerability
ghsa·2024-10-26
CVE-2020-26304 [MEDIUM] CWE-1333 Foundation Regular Expression Denial of Service vulnerability
Foundation Regular Expression Denial of Service vulnerability
Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available.
GHSA
ReDoS in urlregex
ghsa·2024-09-02
CVE-2020-36830 [MEDIUM] CWE-1333 ReDoS in urlregex
ReDoS in urlregex
A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of the component Backtracking. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.5.1 is able to address this issue. The identifier of the patch is e5a085afe6abfaea1d1a78f54c45af9ef43ca1f9. It is recommended to upgrade the affected component.
GHSA
is_js vulnerable to Regular Expression Denial of Service
ghsa·2023-07-06
CVE-2020-26302 [HIGH] CWE-1333 is_js vulnerable to Regular Expression Denial of Service
is_js vulnerable to Regular Expression Denial of Service
is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can cause the regex to loop "forever." This vulnerability was found using a CodeQL query which identifies inefficient regular expressions. is.js has no patch for this issue.
GHSA
GHSA-pff7-wf7w-22h9: An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Servic
ghsa_unreviewed·2022-05-24
CVE-2020-1333 [MEDIUM] CWE-269 GHSA-pff7-wf7w-22h9: An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Servic
An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'.
GHSA
Regular Expression Denial of Service (ReDoS) in lodash
ghsa·2022-01-06
CVE-2020-28500 [MEDIUM] CWE-1333 Regular Expression Denial of Service (ReDoS) in lodash
Regular Expression Denial of Service (ReDoS) in lodash
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the `toNumber`, `trim` and `trimEnd` functions.
Steps to reproduce (provided by reporter Liyuan Chen):
```js
var lo = require('lodash');
function build_blank(n) {
var ret = "1"
for (var i = 0; i < n; i++) {
ret += " "
}
return ret + "1";
}
var s = build_blank(50000) var time0 = Date.now();
lo.trim(s)
var time_cost0 = Date.now() - time0;
console.log("time_cost0: " + time_cost0);
var time1 = Date.now();
lo.toNumber(s) var time_cost1 = Date.now() - time1;
console.log("time_cost1: " + time_cost1);
var time2 = Date.now();
lo.trimEnd(s);
var time_cost2 = Date.now() - time2;
console.log("time_cost2: " + time_cost2);
```
GHSA
Prototype pollution vulnerability in 'predefine'
ghsa·2021-10-12
CVE-2020-28280 [CRITICAL] CWE-1333 Prototype pollution vulnerability in 'predefine'
Prototype pollution vulnerability in 'predefine'
Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of service and may lead to remote code execution.
GHSA
Regular Expression Denial of Service in Leo Editor
ghsa·2021-09-23
CVE-2020-23478 [HIGH] CWE-1333 Regular Expression Denial of Service in Leo Editor
Regular Expression Denial of Service in Leo Editor
Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.
GHSA
regular expression denial-of-service (ReDoS) in Bleach
ghsa·2020-03-30·CVSS 7.5
CVE-2020-6817 [HIGH] CWE-1333 regular expression denial-of-service (ReDoS) in Bleach
regular expression denial-of-service (ReDoS) in Bleach
### Impact
`bleach.clean` behavior parsing style attributes could result in a regular expression denial of service (ReDoS).
Calls to ``bleach.clean`` with an allowed tag with an allowed ``style`` attribute are vulnerable to ReDoS. For example, ``bleach.clean(..., attributes={'a': ['style']})``.
### Patches
3.1.4
### Workarounds
* do not whitelist the style attribute in `bleach.clean` calls
* limit input string length
### References
* https://bugzilla.mozilla.org/show_bug.cgi?id=1623633
* https://www.regular-expressions.info/redos.html
* https://blog.r2c.dev/posts/finding-python-redos-bugs-at-scale-using-dlint-and-r2c/
* https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6817
### Credits
* Reported by schwag09 of r2c
#
GHSA
Denial of Service in uap-core when processing crafted User-Agent strings
ghsa·2020-02-20
CVE-2020-5243 [MEDIUM] CWE-1333 Denial of Service in uap-core when processing crafted User-Agent strings
Denial of Service in uap-core when processing crafted User-Agent strings
### Impact
Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings.
### Patches
Please update uap-core to >= v0.7.3
Downstream packages such as uap-python, uap-ruby etc which depend upon uap-core follow different version schemes.
### Details
Each vulnerable regular expression reported here contains 3 overlapping capture groups. Backtracking has approximately cubic time complexity with respect to the length of the user-agent string.
#### Regex 1:
```
\bSmartWatch *\( *([^;]+) *; *([^;]+) *;
```
is vulnerable in po
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-07-14
Published