CVE-2022-26650

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.13 % (48th)
0.13% Progress
Affected Products 1
Advisories 1

In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters causing a resource exhaustion. This issue affects Apache ShenYu (incubating) 2.4.0, 2.4.1 and 2.4.2 and is fixed in 2.4.3.

Weaknesses
CWE-1333
Inefficient Regular Expression Complexity
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2022-05-17 08:15:06
(2 years ago)
Updated Date
2023-07-12 11:15:09
(14 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Shenyu 2.4.0 cpe:2.3:a:apache:shenyu:2.4.0
  Apache Shenyu 2.4.1 cpe:2.3:a:apache:shenyu:2.4.1
  Apache Shenyu 2.4.2 cpe:2.3:a:apache:shenyu:2.4.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...