Inefficient regular expression complexity in Hawk - CVE-2022-29167
Published: May 31, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions within the Hawk.utils.parseHost() function. A remote attacker can pass specially crafted HTTP header to the application and perform regular expression denial of service (ReDos) attack.
Affected software
Ubuntu
openEuler
nodejs-hawk
node-hawk (Ubuntu package)
How to mitigate CVE-2022-29167
nodejs-hawk - update to 4.1.2-2
node-hawk (Ubuntu package) - addressed in versions 6.0.1+dfsg-1+deb10u1build0.18.04.1, 7.1.2+dfsg-1ubuntu0.1, 8.0.1+dfsg-1ubuntu0.22.04.1, 8.0.1+dfsg-1ubuntu0.22.10.1