HIGH7.5
GHSA-rc47-6667-2j5j
http-cache-semantics vulnerable to Regular Expression Denial of Service
Quick fix
GHSA-rc47-6667-2j5j — http-cache-semantics: upgrade to the fixed version with the command below.
npm install http-cache-semantics@4.1.1Details
http-cache semantics contains an Inefficient Regular Expression Complexity , leading to Denial of Service. This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.webjars.npm:http-cache-semantics
Introduced in:
0Fixed in: 4.1.1Fix
# pom.xml: bump <version>4.1.1</version> for org.webjars.npm:http-cache-semanticsReferences
- https://nvd.nist.gov/vuln/detail/CVE-2022-25881[ADVISORY]
- https://github.com/kornelski/http-cache-semantics/commit/560b2d8ef452bbba20ffed69dc155d63ac757b74[WEB]
- https://github.com/kornelski/http-cache-semantics[PACKAGE]
- https://github.com/kornelski/http-cache-semantics/blob/master/index.js%23L83[WEB]
- https://security.netapp.com/advisory/ntap-20230622-0008[WEB]
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3253332[WEB]
- https://security.snyk.io/vuln/SNYK-JS-HTTPCACHESEMANTICS-3248783[WEB]