loader-utils (JS package) < 3.2.1 - Regular Expression Denial of Service

2022-10-11 00:00
Anonymous

Strategic Overview

Status
Patched in 2.4.4
Affected PluginSimple Page Ordering
Affected Version<= 2.4.3
CVSS3.7Low
CVECVE-2022-37599
View all Simple Page Ordering vulnerabilities

Vulnerability Overview

The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the interpolateName function due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.

Technical Analysis

REMEDIATION: Update to version 2.4.4, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C