Bug 1224296 - VUL-0: CVE-2024-4068: velociraptor: the npm package `braces` fails to limit the number of characters it can handle, which could lead to Memory Exhaustion
Summary: VUL-0: CVE-2024-4068: velociraptor: the npm package `braces` fails to limit t...
Status: NEW
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Antonio Teixeira
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/405385/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-4068:7.5:(AV:N...
Keywords:
Depends on:
Blocks: CVE-2024-4068
  Show dependency treegraph
 
Reported: 2024-05-15 11:53 UTC by SMASH SMASH
Modified: 2024-05-15 12:15 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Gabriele Sonnu 2024-05-15 11:54:28 UTC
A vulnerable version (3.0.2) of the braces package is embedded in:

- SUSE:ALP:Source:Standard:1.0/velociraptor

Upstream issue:

https://github.com/micromatch/braces/issues/35