GHSA-xr9w-x6gw-c9mj

Suggest an improvement
Source
https://github.com/advisories/GHSA-xr9w-x6gw-c9mj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-xr9w-x6gw-c9mj/GHSA-xr9w-x6gw-c9mj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xr9w-x6gw-c9mj
Withdrawn
2023-04-03T17:18:44Z
Published
2023-02-25T06:30:21Z
Modified
2023-04-03T17:18:44Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Duplicate advisory: Deno vulnerable to Regular Expression Denial of Service
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-jc97-h3h9-7xh6. This link is maintained to preserve external references.

Original Description

Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server. This issue has been patched in version 1.31.0.

Database specific
{
    "cwe_ids":  [
        "CWE-1333"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-02-28T14:00:55Z",
    "nvd_published_at":  "2023-02-25T05:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

crates.io / deno

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.31.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-xr9w-x6gw-c9mj/GHSA-xr9w-x6gw-c9mj.json"