PT-2023-12409 · Unknown · Woorank Robots-Txt-Guard

CVE-2021-4305

·

Publicado

2023-01-05

·

Atualizado

2024-05-17

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Woorank robots-txt-guard (affected versions not specified)
Description A vulnerability was found in the function makePathPattern of the file lib/patterns.js. The manipulation of the argument pattern leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used.
Recommendations Apply a patch to fix this issue, specifically the patch c03827cd2f9933619c23894ce7c98401ea824020. As a temporary workaround, consider restricting the use of the makePathPattern function until a patch is available.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-4305
GHSA-6G33-8W2Q-4HXV

Produtos afetados

Woorank Robots-Txt-Guard