NA

CVE-2022-25883

Published: 21/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Versions of the package semver prior to 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

Vulnerable Product Search on Vulmon Subscribe to Product

npmjs semver

Vendor Advisories

Synopsis Important: Red Hat JBoss Enterprise Application Platform 7413 security update on RHEL 7 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Applicatio ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7413 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat JBoss Enterprise Application Platform 74Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scori ...
Synopsis Moderate: Migration Toolkit for Runtimes security, bug fix and enhancement update Type/Severity Security Advisory: Moderate Topic Migration Toolkit for Runtimes 124 releaseRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a de ...
Synopsis Important: Network Observability 140 for OpenShift Type/Severity Security Advisory: Important Topic Network Observability is an OpenShift operator that deploys a monitoring pipeline to collect and enrich network flows that are produced by the Network Observability eBPF agentThe operator provides dashboards, metrics, and keeps flow ...
Synopsis Important: nodejs:16 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the nodejs:16 module is now available for Red Hat Enterprise Linux 8Red Hat Product Se ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7413 security update on RHEL 8 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Applicatio ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7413 security update on RHEL 9 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Applicatio ...
Synopsis Moderate: Logging Subsystem 574 - Red Hat OpenShift bug fix and security update Type/Severity Security Advisory: Moderate Topic Logging Subsystem 574 - Red Hat OpenShiftRed Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed ...
Synopsis Important: nodejs:18 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the nodejs:18 module is now available for Red Hat Enterprise Linux 9Red Hat Product Se ...
Synopsis Important: nodejs:16 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the nodejs:16 module is now available for Red Hat Enterprise Linux 86 Extended Update ...
Synopsis Moderate: Migration Toolkit for Containers (MTC) 182 security and bug fix update Type/Severity Security Advisory: Moderate Topic The Migration Toolkit for Containers (MTC) 182 is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base ...
DescriptionThe MITRE CVE dictionary describes this issue as: Versions of the package semver before 752 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range ...

Github Repositories

Grunt module for Swagger specification validation

Grunt module for Swagger specification validation Updated to version v015 v015 2023/09/05 09:30 EDT - Fix CVE-2022-25883 vulnerabilities Updated to version v014 v014 2021/07/20 15:34 EDT - Fix CVE-2020-7729 vulnerabilities Updated to version v013 v010 This is an initial public release v011 Fix error v012 Fix error in jshint@255 v013 Updated the link as

MATLAB language server MATLAB® language server implements the Microsoft® Language Server Protocol for the MATLAB language MATLAB language server requires MATLAB version R2021a or later Features Implemented MATLAB language server implements several Language Server Protocol features and their related services: Code diagnostics — publishDiagnostics Quick fixes &m

POC for CVE-2022-25883 SemVer Regular Expression Denial of Service Usage: npm i semver@750 watch time node indexjs increase the repetition value