GHSA-wqg7-vrj7-v82h

Suggest an improvement
Source
https://github.com/advisories/GHSA-wqg7-vrj7-v82h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-wqg7-vrj7-v82h/GHSA-wqg7-vrj7-v82h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wqg7-vrj7-v82h
Aliases
Published
2018-08-31T06:22:50Z
Modified
2023-11-08T03:59:46Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Mosca REDoS Vulnerability
Details

This vulnerability allows remote attackers to deny service on vulnerable installations of npm mosca 2.8.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of topics. A crafted regular expression can cause the broker to crash. An attacker can leverage this vulnerability to deny access to the target system.

Database specific
{
    "cwe_ids":  [
        "CWE-185",
        "CWE-20"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T22:01:00Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / mosca

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.8.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-wqg7-vrj7-v82h/GHSA-wqg7-vrj7-v82h.json"