Vulnerability Description
The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Git-Url-Parse Project | Git-Url-Parse | <= 0.4.4 |
Related Weaknesses (CWE)
References
- https://github.com/tjtelan/git-url-parse-rs/issues/51ExploitIssue TrackingThird Party Advisory
- https://lib.rs/crates/git-url-parseProduct
- https://github.com/tjtelan/git-url-parse-rs/issues/51ExploitIssue TrackingThird Party Advisory
- https://lib.rs/crates/git-url-parseProduct
FAQ
What is CVE-2023-33290?
CVE-2023-33290 is a vulnerability with a CVSS score of 7.5 (HIGH). The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python).
How severe is CVE-2023-33290?
CVE-2023-33290 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-33290?
Check the references section above for vendor advisories and patch information. Affected products include: Git-Url-Parse Project Git-Url-Parse.