CVE-2022-38900: Input Validation
A flaw was found in decode-uri-component. This issue occurs due to a specially crafted input, resulting in a denial of service.
Other sources
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
decode-uri-component is vulnerable to a denial of service, caused by improper input validation by the decodeComponents function. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/decode-uri-componentto a version that resolves this vulnerability.Fixed in 0.2.1 - Upgrade
Upgrade
redhat/rh-nodejs14to a version that resolves this vulnerability.Fixed in 0:3.6-2.el7 - Upgrade
Upgrade
redhat/rh-nodejs14-nodejsto a version that resolves this vulnerability.Fixed in 0:14.21.3-2.el7 - Upgrade
Upgrade
redhat/decode-uri-componentto a version that resolves this vulnerability.Fixed in 0.2.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-38900?
CVE-2022-38900 is a vulnerability in decode-uri-component 0.2.0 that allows an attacker to cause a denial of service by providing a specially crafted input.
How does CVE-2022-38900 impact the software?
CVE-2022-38900 can result in a denial of service when the vulnerable version of decode-uri-component (0.2.0) processes a malicious input.
What is the severity of CVE-2022-38900?
The severity of CVE-2022-38900 is high, with a severity score of 7.5.
How can I fix CVE-2022-38900?
To mitigate CVE-2022-38900, update decode-uri-component to version 0.2.1 or higher.
Where can I find more information about CVE-2022-38900?
For more information about CVE-2022-38900, you can visit the following sources: CVE (https://www.cve.org/CVERecord?id=CVE-2022-38900), NVD (https://nvd.nist.gov/vuln/detail/CVE-2022-38900), GitHub Advisory (https://github.com/advisories/GHSA-w573-4hg7-7wgq), Red Hat Bugzilla (https://bugzilla.redhat.com/show_bug.cgi?id=2170644), and Red Hat Security Advisory (https://access.redhat.com/errata/RHSA-2023:1743).