http-cache-semantics < 4.1.1 - Regular Expression Denial of Service (ReDoS)

2023-02-23 00:00
Anonymous

Strategic Overview

Status
Patched in 2.7.4
Affected PluginSimple Local Avatars
Affected Version<= 2.7.3
CVSS5.3Medium
CVECVE-2022-25881
View all Simple Local Avatars vulnerabilities

Vulnerability Overview

The package http-cache-semantics is vulnerable to Regular Expression Denial of Service (ReDoS) in versions before 4.1.1 via the cache-control HTTP header. WordPress plugins and themes may be using this package, however, they may not be vulnerable to exploitation.

Technical Analysis

REMEDIATION: Update to version 2.7.4, or a newer patched version --- IDENTIFIER: CWE-1333 (Inefficient Regular Expression Complexity) The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C