CVE-2022-25881
http-cache-semantics < 4.1.1 - Regular Expression Denial of Service (ReDoS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.
Esto afecta a las versiones del paquete http-cache-semantics anteriores a la 4.1.1. El problema se puede explotar mediante valores de encabezado de solicitud maliciosos enviados a un servidor, cuando ese servidor lee la política de caché de la solicitud utilizando esta librería.
A flaw was found in http-cache-semantics. When the server reads the cache policy from the request using this library, a Regular Expression Denial of Service occurs, caused by malicious request header values sent to the server.
The package http-cache-semantics is vulnerable to Regular Expression Denial of Service (ReDoS) in versions before 4.1.1 via the cache-control HTTP header. WordPress plugins and themes may be using this package, however, they may not be vulnerable to exploitation.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-24 CVE Reserved
- 2023-01-31 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-09-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-1333: Inefficient Regular Expression Complexity
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/kornelski/http-cache-semantics/blob/master/index.js%23L83 | Broken Link | |
https://security.netapp.com/advisory/ntap-20230622-0008 |
URL | Date | SRC |
---|---|---|
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3253332 | 2024-08-03 | |
https://security.snyk.io/vuln/SNYK-JS-HTTPCACHESEMANTICS-3248783 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2022-25881 | 2023-10-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2165824 | 2023-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Http-cache-semantics Project Search vendor "Http-cache-semantics Project" | Http-cache-semantics Search vendor "Http-cache-semantics Project" for product "Http-cache-semantics" | < 4.1.1 Search vendor "Http-cache-semantics Project" for product "Http-cache-semantics" and version " < 4.1.1" | node.js |
Affected
|