CVE-2025-4215
Last modified
CVE-2025-4215 is a low-severity vulnerability rated 2.3/10 on the CVSS scale. A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filters.js of the component UI. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.63.3b17 is able to address this issue. The patch is identified as eaedaf5b10d2f7857c6b77fbf7d4a80681d4d46c. It is recommended to upgrade the affected component.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ublockorigin | Ublock Origin | < 1.63.3 | — |
| Ublockorigin | Ublock Origin | 1.63.3 | Beta1 |
| Debian | Debian Linux | 11.0 | — |
References
- https://vuldb.com/?ctiid.307194Permissions Required, VDB Entry
- https://vuldb.com/?id.307194Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.562301Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-4215?
How severe is CVE-2025-4215?
How do I fix CVE-2025-4215?
Are you affected by CVE-2025-4215?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
