CVE-2020-26304

Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:foundation:foundation:*:*:*:*:*:*:*:*

History

13 Nov 2024, 19:58

Type Values Removed Values Added
CWE CWE-1333
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:foundation:foundation:*:*:*:*:*:*:*:*
First Time Foundation foundation
Foundation
References () https://securitylab.github.com/advisories/GHSL-2020-290-redos-foundation-sites/ - () https://securitylab.github.com/advisories/GHSL-2020-290-redos-foundation-sites/ - Exploit, Third Party Advisory
References () https://github.com/foundation/foundation-sites/issues/12180 - () https://github.com/foundation/foundation-sites/issues/12180 - Issue Tracking, Third Party Advisory

26 Oct 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-26 21:15

Updated : 2024-11-13 19:58


NVD link : CVE-2020-26304

Mitre link : CVE-2020-26304


JSON object : View

Products Affected

foundation

  • foundation
CWE
CWE-1333

Inefficient Regular Expression Complexity