CVE-2024-41655
CVSS V2 None
CVSS V3 None
Description
TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable to a Regular Expression Denial of Service (ReDoS) attack when parsing crafted user input. This vulnerability can be exploited by an attacker to perform DoS attacks on any service that uses any `tf2-item-format` to parse user input. Version `5.9.14` contains a fix for the issue.
Overview
- CVE ID
- CVE-2024-41655
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-07-23T14:49:34.078Z
- Last Modified Date
- 2024-07-23T14:49:34.078Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/danocmx/node-tf2-item-format/security/advisories/GHSA-8h55-q5qq-p685 | x_refsource_CONFIRM |
https://github.com/danocmx/node-tf2-item-format/commit/5cffcc16a9261d6a937bda72bfe6830e02e31eec | x_refsource_MISC |
https://github.com/danocmx/node-tf2-item-format/releases/tag/v5.9.14 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-41655 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-41655 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-07-24 13:02:36 | Added to TrackCVE |