CVE-2024-41818
CVSS V2 None
CVSS V3 None
Description
fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.
Overview
- CVE ID
- CVE-2024-41818
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-07-29T15:56:38.999Z
- Last Modified Date
- 2024-07-29T15:56:38.999Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-mpg4-rc92-vx8v | x_refsource_CONFIRM |
https://github.com/NaturalIntelligence/fast-xml-parser/commit/d0bfe8a3a2813a185f39591bbef222212d856164 | x_refsource_MISC |
https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/src/v5/valueParsers/currency.js#L10 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-41818 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-41818 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-07-30 13:14:50 | Added to TrackCVE |