216.73.217.22

CVE-2024-21539

· Published 19/11/2024 05:15 · Modified 19/11/2024 21:57

Labels: CVE-2024-21539 2024-11-19CVE-2024-21539CWE-1333CWE-770[email protected]

Essential information

Published
19/11/2024 05:15
Modified
19/11/2024 21:57
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References