Hawk before 3.1.3 and 4.x before 4.1.1 allow remote attackers to cause a denial of service (CPU consumption or partial outage) via a long (1) header or (2) URI that is matched against an improper regular expression.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:hawk_project:hawk:3.1.2:*:*:*:*:*:*:*",
"cpe:2.3:a:hawk_project:hawk:4.1.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "3.1.2"
},
{
"last_affected": "3.1.2"
},
{
"introduced": "4.1.0"
},
{
"last_affected": "4.1.0"
}
],
"vendor_product": "hawk_project:hawk",
"source": "CPE_STRING"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.1.3"
},
{
"introduced": "4.x"
},
{
"fixed": "4.1.1"
}
],
"source": [
"DESCRIPTION",
"REFERENCES"
]
}