CVE-2022-24373
Description
The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper usage of regular expression in the parser of Colors.js.
CWE
- CWE-1333 — CWE-1333 Inefficient Regular Expression Complexity
Affected
- n/a / react-native-reanimated — v=unspecified <3.0.0-rc.1 [affected]
CVSS
- 3.1 score=5.3 severity=MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P
References
- https://security.snyk.io/vuln/SNYK-JS-REACTNATIVEREANIMATED-2949507 x_refsource_MISC
- https://github.com/software-mansion/react-native-reanimated/pull/3382 x_refsource_MISC
- https://github.com/software-mansion/react-native-reanimated/pull/3382/commits/7adf06d0c59382d884a04be86a96eede3d0432fa x_refsource_MISC
- https://github.com/software-mansion/react-native-reanimated/releases/tag/3.0.0-rc.1 x_refsource_MISC
Source
cvelistV5-main/cves/2022/24xxx/CVE-2022-24373.json