CVE-2023-32758
Summary
| CVE | CVE-2023-32758 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-15 04:15:00 UTC |
| Updated | 2023-06-09 19:15:00 UTC |
| Description | giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an http:// URL), and that package's author placed a ReDoS attack payload in a URL used by the package. |
Risk And Classification
Problem Types: CWE-1333
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Coala | Git-url-parse | All | All | All | All |
| Application | Semgrep | Semgrep | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix other source of slowness in git URL parser + limit URL length to 1024 by mjambon · Pull Request #7955 · returntocorp/semgrep · GitHub | MISC | github.com | |
| git-url-parse/parser.py at master · coala/git-url-parse · GitHub | MISC | github.com | |
| git-url-parse · PyPI | MISC | pypi.org | |
| Fix for ReDoS vulnerability by mjambon · Pull Request #7943 · returntocorp/semgrep · GitHub | MISC | github.com | |
| fix(cli): git URL parsing for subgroups by brandonspark · Pull Request #7611 · returntocorp/semgrep · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.