Lucene search

K
hackeroneHackeronanywhereH1:1879548
HistoryFeb 20, 2023 - 11:44 a.m.

Mozilla Core Services: Missing Function Level Access Control in Mozilla formula containsRegular Expression Denial of Service (CVE-2023-25166)

2023-02-2011:44:40
hackeronanywhere
hackerone.com
7
mozilla
function level access control
regular expression denial of service
cve-2023-25166
sideway formula
github
bedrock
bug bounty

0.001 Low

EPSS

Percentile

34.6%

sideway/formula package which is used in https://github.com/mozilla/bedrock contains Regular Expression Denial of Service (ReDoS) Vulnerability. The issue was fixed by upgrading the package to a secure version.

0.001 Low

EPSS

Percentile

34.6%