CVE-2021-45470: High severity circl cve-search vulnerability
Published Dec 23, 2021
·Updated
lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.
Affected Software
1 affected component
Circl Cve-search<4.1.0
Remediation
Patch Available
Event History
Dec 23, 2021
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45470?
CVE-2021-45470 has a moderate severity level due to its potential for causing denial of service through regular expression injection.
2
How do I fix CVE-2021-45470?
To fix CVE-2021-45470, upgrade cve-search to version 4.1.0 or later.
3
What impact can CVE-2021-45470 have on my system?
CVE-2021-45470 can lead to regular expression denial of service, potentially causing application slowdown or crash.
4
In which versions of cve-search is CVE-2021-45470 present?
CVE-2021-45470 is present in all versions of cve-search prior to 4.1.0.
5
Is CVE-2021-45470 exploit related to user input?
Yes, CVE-2021-45470 allows exploit through crafted user input that triggers regular expression injection.