CVE-2022-3517

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

History

21 Jul 2023, 21:04

Type Values Removed Values Added
CWE CWE-400 CWE-1333

28 Mar 2023, 17:14

Type Values Removed Values Added
CWE NVD-CWE-Other CWE-400
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UM6XJ73Q3NAM5KSGCOKJ2ZIA6GUWUJLK/ - Mailing List, Third Party Advisory
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/01/msg00011.html - Mailing List, Third Party Advisory
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTEUUTNIEBHGKUKKLNUZSV7IEP6IP3Q3/ - Mailing List, Third Party Advisory
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

19 Oct 2022, 17:56

Type Values Removed Values Added
CPE cpe:2.3:a:minimatch_project:minimatch:*:*:*:*:*:node.js:*:*
CWE CWE-400 NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://github.com/isaacs/minimatch/commit/a8763f4388e51956be62dc6025cec1126beeb5e6 - (MISC) https://github.com/isaacs/minimatch/commit/a8763f4388e51956be62dc6025cec1126beeb5e6 - Patch, Third Party Advisory
References (MISC) https://github.com/grafana/grafana-image-renderer/issues/329 - (MISC) https://github.com/grafana/grafana-image-renderer/issues/329 - Issue Tracking, Patch, Third Party Advisory

17 Oct 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-17 20:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-3517

Mitre link : CVE-2022-3517

CVE.ORG link : CVE-2022-3517


JSON object : View

Products Affected

debian

  • debian_linux

fedoraproject

  • fedora

minimatch_project

  • minimatch
CWE
CWE-1333

Inefficient Regular Expression Complexity

CWE-400

Uncontrolled Resource Consumption