CVE-2022-31110
MEDIUM5.3EPSS 0.56%Denial of Service (DoS) vulnerability in RSSHub
發布日:2022/6/23修改日:2023/11/8
描述
### Impact Passing some special values to the `filter` and `filterout` parameters can cause an abnormally high CPU. Impact on the performance of the servers and RSSHub services. ### Patches It is fixed in 5c4177441417b44a6e45c3c63e9eac2504abeb5b , please update to this or the later versions as soon as possible. ### References Full report: https://github.com/DIYgod/RSSHub/issues/10045 ### For more information If you have any questions or comments about this advisory: * Open an issue in <https://github.com/DIYgod/RSSHub/issues> * Email us at [[email protected]](mailto:[email protected]) ### Credits @Rongronggg9
受影響套件(1)
- npm/rsshubfrom 0, <= 1.0.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-31110
- PATCHhttps://github.com/DIYgod/RSSHub
- WEBhttps://github.com/DIYgod/RSSHub/commit/4671720f4c5e1aaaad8fcc1dce684b6546baf2ff
- WEBhttps://github.com/DIYgod/RSSHub/commit/5c4177441417b44a6e45c3c63e9eac2504abeb5b
- WEBhttps://github.com/DIYgod/RSSHub/issues/10045
- WEBhttps://github.com/DIYgod/RSSHub/security/advisories/GHSA-jvxx-v45p-v5vf