CVE-2022-29158
Summary
| CVE | CVE-2022-29158 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-02 07:15:00 UTC |
| Updated | 2023-07-21 16:38:00 UTC |
| Description | Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599 |
Risk And Classification
Problem Types: CWE-1333
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| N/A | CONFIRM | lists.apache.org | |
| oss-security - Apache OFBiz - Regular Expression Denial of Service (ReDoS) (CVE-2022-29158) | MLIST | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Tony Torralba and Joseph Farebrother from the GitHub CodeQL team.
There are currently no legacy QID mappings associated with this CVE.