Lucene search

K
cve@huntrdevCVE-2023-2251
HistoryApr 24, 2023 - 3:15 p.m.

CVE-2023-2251

2023-04-2415:15:08
CWE-248
@huntrdev
web.nvd.nist.gov
79
cve-2023-2251
github
repository
eemeli/yaml
nvd
uncaught exception
security vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

42.9%

Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.

Affected configurations

Nvd
Node
yaml_projectyamlRange2.0.0-52.2.2node.js

CNA Affected

[
  {
    "vendor": "eemeli",
    "product": "eemeli/yaml",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "2.0.0-5",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

42.9%