CVE-2024-4068
Last modified
CVE-2024-4068 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. EPSS estimates a 1.47% chance of exploitation in the next 30 days.
Description
The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jonschlinkert | Braces | < 3.0.3 |
References
- https://devhub.checkmarx.com/cve-details/CVE-2024-4068/Third Party Advisory
- https://github.com/micromatch/braces/issues/35Issue Tracking
- https://github.com/micromatch/braces/pull/37Exploit, Issue Tracking, Patch
- https://github.com/micromatch/braces/pull/40Issue Tracking, Patch
- https://devhub.checkmarx.com/cve-details/CVE-2024-4068/Third Party Advisory
- https://github.com/micromatch/braces/issues/35Issue Tracking
- https://github.com/micromatch/braces/pull/37Exploit, Issue Tracking, Patch
- https://github.com/micromatch/braces/pull/40Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4068?
How severe is CVE-2024-4068?
How do I fix CVE-2024-4068?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-40673In Source of ZipFile.java, there is a possible way for an at…6.5
- CVE-2024-40674In validateSsid of WifiConfigurationUtil.java, there is a po…5.3
- CVE-2024-40675In parseUriInternal of Intent.java, there is a possible infi…7.5
- CVE-2024-40676In checkKeyIntent of AccountManagerService.java, there is a …7.7
- CVE-2024-40677In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java,…8.4
- CVE-2024-40679IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Se…5.5
- CVE-2024-40680IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cau…5.5
- CVE-2024-40681IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 C…8.8
- CVE-2024-40682IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.…5.5
- CVE-2024-40683IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.…6.3
- CVE-2024-40684IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.…9.8
- CVE-2024-40685IBM Operations Analytics – Log Analysis versions 1.3.5.0 thr…4.3
Are you affected by CVE-2024-4068?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
