VulnerabilityAnalyzed
CVE-2022-25883
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
HIGH 7.5EPSS 2.76%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.76% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1333
- Affected
- npmjs/semver
- Source
- report@snyk.io
References
- https://github.com/npm/node-semver/blob/main/classes/range.js%23L97-L104Broken Link
- https://github.com/npm/node-semver/blob/main/internal/re.js%23L138Broken Link
- https://github.com/npm/node-semver/blob/main/internal/re.js%23L160Broken Link
- https://github.com/npm/node-semver/commit/717534ee353682f3bcf33e60a8af4292626d4441Patch, Third Party Advisory
- https://github.com/npm/node-semver/pull/564Patch, Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795Exploit, Patch, Third Party Advisory
- https://github.com/npm/node-semver/blob/main/classes/range.js%23L97-L104Broken Link
- https://github.com/npm/node-semver/blob/main/internal/re.js%23L138Broken Link
- https://github.com/npm/node-semver/blob/main/internal/re.js%23L160Broken Link
- https://github.com/npm/node-semver/commit/717534ee353682f3bcf33e60a8af4292626d4441Patch, Third Party Advisory
- https://github.com/npm/node-semver/pull/564Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20241025-0004/Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795Exploit, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.