Vulnerability Description
formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hapi | Formula | < 3.0.1 |
Related Weaknesses (CWE)
References
- https://github.com/hapijs/formula/commit/9fbc20a02d75ae809c37a610a57802cd1b41b3fPatch
- https://github.com/hapijs/formula/security/advisories/GHSA-c2jc-4fpr-4vhgVendor Advisory
- https://github.com/hapijs/formula/commit/9fbc20a02d75ae809c37a610a57802cd1b41b3fPatch
- https://github.com/hapijs/formula/security/advisories/GHSA-c2jc-4fpr-4vhgVendor Advisory
FAQ
What is CVE-2023-25166?
CVE-2023-25166 is a vulnerability with a CVSS score of 5.5 (MEDIUM). formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should ...
How severe is CVE-2023-25166?
CVE-2023-25166 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25166?
Check the references section above for vendor advisories and patch information. Affected products include: Hapi Formula.