CVE-2018-20801: High severity highcharts vulnerability
Published Mar 14, 2019
·Updated
In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a denial of service attack against the SVGRenderer component, aka ReDoS.
Affected Software
1 affected component
Highcharts Highcharts<6.1.0
Remediation
Event History
Mar 14, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20801?
CVE-2018-20801 has a medium severity level due to its potential to cause a denial of service.
2
How do I fix CVE-2018-20801?
To fix CVE-2018-20801, update Highcharts to version 6.1.0 or later.
3
What components are affected by CVE-2018-20801?
CVE-2018-20801 affects the SVGRenderer component in Highcharts JS.
4
What type of attack can CVE-2018-20801 facilitate?
CVE-2018-20801 can facilitate a denial of service attack through the use of backtracking regular expressions.
5
In which version of Highcharts is CVE-2018-20801 not present?
CVE-2018-20801 is not present in Highcharts version 6.1.0 and above.