Vulnerability Description
lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Circl | Cve-Search | < 4.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/cve-search/cve-search/commit/c621f9f0693a728b93ff3b964f948a1dPatchThird Party Advisory
- https://github.com/cve-search/cve-search/compare/v4.0...v4.1.0Third Party Advisory
- https://github.com/cve-search/cve-search/pull/629ExploitPatchThird Party Advisory
- https://github.com/cve-search/cve-search/commit/c621f9f0693a728b93ff3b964f948a1dPatchThird Party Advisory
- https://github.com/cve-search/cve-search/compare/v4.0...v4.1.0Third Party Advisory
- https://github.com/cve-search/cve-search/pull/629ExploitPatchThird Party Advisory
FAQ
What is CVE-2021-45470?
CVE-2021-45470 is a vulnerability with a CVSS score of 7.5 (HIGH). lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.
How severe is CVE-2021-45470?
CVE-2021-45470 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45470?
Check the references section above for vendor advisories and patch information. Affected products include: Circl Cve-Search.