Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33731
HistoryJan 17, 2022 - 2:04 p.m.

Regular Expression Denial Of Service (ReDoS)

2022-01-1714:04:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
redos
vulnerability
software
backtracking
injection

EPSS

0.002

Percentile

60.8%

marked is vulnerable to regular expression denial of service. An attacker is able to induce the system into backtracking by injecting a maliciously crafted string via a variable inline.reflink search.