Vulnerability Description
GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vulnerability that may lead to Denial of Service. This has been patched in 2.4 and 3.0 See this pull request for the fix: https://github.com/graphhopper/graphhopper/pull/2304
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Graphhopper | Graphhopper | >= 2.0, < 2.4 |
Related Weaknesses (CWE)
References
- https://github.com/graphhopper/graphhopper/commit/eb189be1fa7443ebf4ae881e737a18PatchThird Party Advisory
- https://github.com/graphhopper/graphhopper/pull/2304PatchThird Party Advisory
- https://github.com/graphhopper/graphhopper/security/advisories/GHSA-hf44-3mx6-vhThird Party Advisory
- https://github.com/graphhopper/graphhopper/commit/eb189be1fa7443ebf4ae881e737a18PatchThird Party Advisory
- https://github.com/graphhopper/graphhopper/pull/2304PatchThird Party Advisory
- https://github.com/graphhopper/graphhopper/security/advisories/GHSA-hf44-3mx6-vhThird Party Advisory
FAQ
What is CVE-2021-29506?
CVE-2021-29506 is a vulnerability with a CVSS score of 6.5 (MEDIUM). GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vulnerability that may lead to Denial of Service. Thi...
How severe is CVE-2021-29506?
CVE-2021-29506 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-29506?
Check the references section above for vendor advisories and patch information. Affected products include: Graphhopper Graphhopper.