CVE-2024-4068
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: 596c5446-0ce5-4ba2-aa66-48b3b757a647 (Secondary)
Description
The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.
Affected (1)
Products: Jonschlinkert: Braces
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.3 |
Related CWEs
CWE-1050
Excessive Platform Resource Consumption within a Loop
The product has a loop body or loop condition that contains a control element that directly or
indirectly consumes platform resources, e.g. messaging, sessions, locks, or file
descriptors.
CWE-400
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
References (10)
Source: 596c5446-0ce5-4ba2-aa66-48b3b757a647
Third Party Advisory
Source: 596c5446-0ce5-4ba2-aa66-48b3b757a647
Patch
Source: 596c5446-0ce5-4ba2-aa66-48b3b757a647
Issue Tracking
Source: 596c5446-0ce5-4ba2-aa66-48b3b757a647
ExploitIssue TrackingPatch
Source: 596c5446-0ce5-4ba2-aa66-48b3b757a647
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Timeline
No history available yet.