Description
This vulnerability allows remote attackers to deny service on vulnerable installations of npm mosca 2.8.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of topics. A crafted regular expression can cause the broker to crash. An attacker can leverage this vulnerability to deny access to the target system. Was ZDI-CAN-6306.
Published: 2018-08-30
Score: 7.5 High
EPSS: 12.4% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wqg7-vrj7-v82h Mosca REDoS Vulnerability
History

No history.

Subscriptions

Mosca Project Mosca
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2024-08-05T08:17:07.813Z

Reserved: 2018-05-31T00:00:00.000Z

Link: CVE-2018-11615

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-30T12:29:00.437

Modified: 2024-11-21T03:43:41.980

Link: CVE-2018-11615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses