Vulnerability Details CVE-2022-22138
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.8%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2022-22138
-
cpe:2.3:a:fast_string_search_project:fast_string_search:-
-
cpe:2.3:a:fast_string_search_project:fast_string_search:1.2.0
-
cpe:2.3:a:fast_string_search_project:fast_string_search:1.2.1
-
cpe:2.3:a:fast_string_search_project:fast_string_search:1.3.0
-
cpe:2.3:a:fast_string_search_project:fast_string_search:1.4.0
-
cpe:2.3:a:fast_string_search_project:fast_string_search:1.4.1
-
cpe:2.3:a:fast_string_search_project:fast_string_search:1.4.2
-
cpe:2.3:a:fast_string_search_project:fast_string_search:1.4.3