decode-uri-component <= 0.2.1 - Denial of Service

2023-01-23 00:00
Anonymous

Strategic Overview

Status
Patched in 1.3.0
Affected Version<= 1.2.1
CVSS7.5High
CVECVE-2022-38900
View all Autopost for X (formerly Autoshare for Twitter) vulnerabilities

Vulnerability Overview

The decode-uri-component is vulnerable to Denial of Service due to improper input validation in versions up to, and including, 0.2.1 when certain search strings are parsed by the decodeUriComponent.

Technical Analysis

REMEDIATION: Update to version 1.3.0, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C