CVE-2022-38900
decode-uri-component <= 0.2.1 - Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
decode-uri-component 0.2.0 es vulnerable a una validación de entrada incorrecta que provoca DoS.
A flaw was found in decode-uri-component. This issue occurs due to a specially crafted input, resulting in a denial of service.
The decode-uri-component is vulnerable to Denial of Service due to improper input validation in versions up to, and including, 0.2.1 when certain search strings are parsed by the decodeUriComponent.
Red Hat Process Automation Manager is an open source business process management suite that combines process management and decision service management and enables business and IT users to create, manage, validate, and deploy process applications and decision services. This asynchronous security patch is an update to Red Hat Process Automation Manager 7. Issues addressed include bypass, denial of service, deserialization, and memory leak vulnerabilities.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2022-08-29 CVE Reserved
- 2022-11-28 CVE Published
- 2025-04-25 CVE Updated
- 2025-04-25 First Exploit
- 2025-06-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (9)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/SamVerschueren/decode-uri-component/issues/5 | 2025-04-25 | |
https://github.com/sindresorhus/query-string/issues/345 | 2025-04-25 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Decode-uri-component Project Search vendor "Decode-uri-component Project" | Decode-uri-component Search vendor "Decode-uri-component Project" for product "Decode-uri-component" | 0.2.0 Search vendor "Decode-uri-component Project" for product "Decode-uri-component" and version "0.2.0" | - |
Affected
|