CVE-2024-4067
Last modified
CVE-2024-4067 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching. This issue was fixed in version 4.0.8.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jonschlinkert | Micromatch | < 4.0.8 |
References
- https://advisory.checkmarx.net/advisory/CVE-2024-4067/Exploit, Third Party Advisory
- https://devhub.checkmarx.com/cve-details/CVE-2024-4067/Third Party Advisory
- https://github.com/micromatch/micromatch/pull/266Issue Tracking, Patch
- https://devhub.checkmarx.com/cve-details/CVE-2024-4067/Third Party Advisory
- https://github.com/micromatch/micromatch/issues/243Issue Tracking
- https://github.com/micromatch/micromatch/pull/247Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4067?
How severe is CVE-2024-4067?
How do I fix CVE-2024-4067?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-4066A vulnerability classified as critical has been found in Ten…8.8
- CVE-2024-40660In setTransactionState of SurfaceFlinger.cpp, there is a pos…7.8
- CVE-2024-40661In mayAdminGrantPermission of AdminRestrictedPermissionsUtil…7.8
- CVE-2024-40662In scheme of Uri.java, there is a possible way to craft a ma…7.8
- CVE-2024-40664In setupAccessibilityServices of AccessibilityFragment.java …6.2
- CVE-2024-40669In TBD of TBD, there is a possible use after free due to a r…8.4
- CVE-2024-40670In TBD of TBD, there is a possible use after free due to a r…8.4
- CVE-2024-40671In DevmemIntChangeSparse2 of devicemem_server.c, there is a …7.8
- CVE-2024-40672In onCreate of ChooserActivity.java, there is a possible way…8.4
- CVE-2024-40673In Source of ZipFile.java, there is a possible way for an at…6.5
- CVE-2024-40674In validateSsid of WifiConfigurationUtil.java, there is a po…5.3
- CVE-2024-40675In parseUriInternal of Intent.java, there is a possible infi…7.5
Are you affected by CVE-2024-4067?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
