{"id":"CVE-2022-36034","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-36034","summary":"Polynomial regular expression used on uncontrolled data in nitrado.js","details":"### Impact\nPossible ReDoS with lib input of `{{` and with many repetitions of `{{|`\n\n### Patches\nPatched in all versions above `0.2.5`\n\n### Workarounds\nNo known work arounds.\n\n### References\n- OWASP: [Regular expression Denial of Service - ReDoS](https://www.owasp.org/index.php/Regular_expression_Denial_of_Service_-_ReDoS)\n- Wikipedia: [ReDoS](https://en.wikipedia.org/wiki/ReDoS).\n- Wikipedia: [Time complexity](https://en.wikipedia.org/wiki/Time_complexity).\n- James Kirrage, Asiri Rathnayake, Hayo Thielecke: [Static Analysis for Regular Expression Denial-of-Service Attack](http://www.cs.bham.ac.uk/~hxt/research/reg-exp-sec.pdf).\n- Common Weakness Enumeration: [CWE-1333](https://cwe.mitre.org/data/definitions/1333.html).\n- Common Weakness Enumeration: [CWE-400](https://cwe.mitre.org/data/definitions/400.html).\n\n\n","published":"2022-08-31T22:23:39Z","modified":"2023-11-08T04:09:58.481300Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"nitrado.js","fixedVersion":"0.2.5"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/cainthebest/nitrado.js/security/advisories/GHSA-vqc4-v8hc-h2jg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36034"},{"type":"PACKAGE","url":"https://github.com/cainthebest/nitrado.js"},{"type":"WEB","url":"https://github.com/cainthebest/nitrado.js/blob/v0.2.5/CHANGELOG.md"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:09:58.481300Z"}}