CVE-2022-31110
MEDIUM5.3EPSS 0.56%Denial of Service (DoS) vulnerability in RSSHub
Published: 6/23/2022Modified: 11/8/2023
Also known as:GHSA-jvxx-v45p-v5vf
Description
### Impact Passing some special values to the `filter` and `filterout` parameters can cause an abnormally high CPU. Impact on the performance of the servers and RSSHub services. ### Patches It is fixed in 5c4177441417b44a6e45c3c63e9eac2504abeb5b , please update to this or the later versions as soon as possible. ### References Full report: https://github.com/DIYgod/RSSHub/issues/10045 ### For more information If you have any questions or comments about this advisory: * Open an issue in <https://github.com/DIYgod/RSSHub/issues> * Email us at [[email protected]](mailto:[email protected]) ### Credits @Rongronggg9
Affected packages (1)
- npm/rsshubfrom 0, <= 1.0.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
References (6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-31110
- PATCHhttps://github.com/DIYgod/RSSHub
- WEBhttps://github.com/DIYgod/RSSHub/commit/4671720f4c5e1aaaad8fcc1dce684b6546baf2ff
- WEBhttps://github.com/DIYgod/RSSHub/commit/5c4177441417b44a6e45c3c63e9eac2504abeb5b
- WEBhttps://github.com/DIYgod/RSSHub/issues/10045
- WEBhttps://github.com/DIYgod/RSSHub/security/advisories/GHSA-jvxx-v45p-v5vf