CVE-2024-4067: Regular Expression Denial of Service in micromatch
Node.js micromatch module is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw in micromatch.braces() in index.js. By sending a specially crafted payload, a remote attacker could exploit this vulnerability to increase the consumption time until the application hangs or slows down.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4067?
CVE-2024-4067 is classified as a denial of service vulnerability due to a regex ReDoS flaw in the micromatch module.
How do I fix CVE-2024-4067?
To fix CVE-2024-4067, upgrade the micromatch package to version 4.0.8 or later.
What software is affected by CVE-2024-4067?
CVE-2024-4067 affects the micromatch module and IBM Cognos Dashboards on Cloud Pak for Data versions up to 5.0.0.
Can CVE-2024-4067 be exploited remotely?
Yes, CVE-2024-4067 can be exploited remotely by sending specially crafted payloads to the affected application.
What is the impact of CVE-2024-4067?
The impact of CVE-2024-4067 includes potential service downtime and resource exhaustion due to increased consumption time.