Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-25844
HistoryMay 01, 2022 - 4:15 p.m.

Code injection

2022-05-0116:15:00
PRIOn knowledge base
www.prio-n.com
20

7.2 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.8%

The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ’ '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. Note: 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.

CPENameOperatorVersion
angularge1.7.0
fedoraeq35
fedoraeq36

7.2 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.8%