HIGH
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service
Published Oct 14, 2019
7.5
HIGHCVSS 3.1
EPSS 2.28%
Description
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when using the cast option.
Affected products
No data.
Configuration 1
- < 4.4.6
Configuration 2
- 31
No data.
No Red Hat product state for this CVE.
csv-parse
npm
Introduced 0 Fixed 4.4.6
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | csv-parse | 0 | 4.4.6 |
Remediation
No remediation recorded yet.
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0686 Advisory
- https://github.com/adaltas/node-csv-parse/commit/b9d35940c6815cdf1dfd6b21857a1f6d0fd51e4a x_refsource_MISCPatchThird Party Advisory
- https://github.com/advisories/GHSA-582f-p4pg-xc74 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/
- https://nvd.nist.gov/vuln/detail/CVE-2019-17592
- https://security.netapp.com/advisory/ntap-20191127-0002/ x_refsource_CONFIRMThird Party Advisory
- https://www.npmjs.com/advisories/1171 x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0686 | Advisory | |
| https://github.com/adaltas/node-csv-parse/commit/b9d35940c6815cdf1dfd6b21857a1f6d0fd51e4a | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-582f-p4pg-xc74 | Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/ | ||
| https://nvd.nist.gov/vuln/detail/CVE-2019-17592 | ||
| https://security.netapp.com/advisory/ntap-20191127-0002/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.npmjs.com/advisories/1171 | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 14, 2019
Updated Aug 5, 2024
Reserved Oct 14, 2019
Link CVE-2019-17592
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-0686 GHSA-582F-P4PG-XC74 Assigner mitre
Published Oct 14, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-0686