Lucene search

K
cvelistApacheCVELIST:CVE-2022-29158
HistorySep 02, 2022 - 7:10 a.m.

CVE-2022-29158 Regular Expression Denial of Service (ReDoS) vulnerability in Apache OFBiz

2022-09-0207:10:20
CWE-1333
apache
www.cve.org
1
cve-2022-29158
redos
apache ofbiz
regular expression denial of service
upgrade
patch
urls

0.001 Low

EPSS

Percentile

51.1%

Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599

CNA Affected

[
  {
    "product": "Apache OFBiz",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "18.12.05",
        "status": "affected",
        "version": "Apache OFBiz",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

51.1%

Related for CVELIST:CVE-2022-29158