CVE-2020-26304

Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:foundation:foundation:*:*:*:*:*:*:*:*

History

13 Nov 2024, 19:58

Type Values Removed Values Added
CPE cpe:2.3:a:foundation:foundation:*:*:*:*:*:*:*:*
First Time Foundation
Foundation foundation
References () https://github.com/foundation/foundation-sites/issues/12180 - () https://github.com/foundation/foundation-sites/issues/12180 - Issue Tracking, Third Party Advisory
References () https://securitylab.github.com/advisories/GHSL-2020-290-redos-foundation-sites/ - () https://securitylab.github.com/advisories/GHSL-2020-290-redos-foundation-sites/ - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

28 Oct 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) Foundation es un framework de trabajo front-end. Las versiones 6.3.3 y anteriores contienen una o más expresiones regulares que son vulnerables a la denegación de servicio por expresión regular (ReDoS). Al momento de la publicación, se desconoce si hay alguna solución disponible.

26 Oct 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-26 21:15

Updated : 2024-11-13 19:58


NVD link : CVE-2020-26304

Mitre link : CVE-2020-26304

CVE.ORG link : CVE-2020-26304


JSON object : View

Products Affected

foundation

  • foundation
CWE
CWE-1333

Inefficient Regular Expression Complexity