Navigate endpoint is vulnerable to regex injection that may lead to Denial of Service.
Moderate severity
GitHub Reviewed
Published
May 11, 2021
in
graphhopper/graphhopper
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 13, 2021
Reviewed
May 19, 2021
Published to the GitHub Advisory Database
May 19, 2021
Last updated
Feb 1, 2023
Impact
The regex injection that may lead to Denial of Service.
Patches
Will be patched in 2.4 and 3.0
Workarounds
Versions lower than 2.x are only affected if the navigation module is added
References
See this pull request for the fix: graphhopper/graphhopper#2304
If you have any questions or comments about this advisory please send us an Email or create a topic here.
References