Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
Vulnerability Description
React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework Mode applications as well as Remix applications. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in react-router version 7.15.0 and @remix-run/server-runtime version 2.17.5.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
AuthKit React Router Library 资源管理错误漏洞
Vulnerability Description
AuthKit React Router Library是WorkOS开源的一个在React Router 7中使用的身份验证和会话助手。 AuthKit React Router Library 7.0.0版本至7.14.x版本和@remix-run/server-runtime 2.10.0版本至2.17.4版本存在资源管理错误漏洞,该漏洞源于__manifest端点中无界路径扩展导致服务器资源消耗不成比例,可能导致响应时间下降或服务不可用。
CVSS Information
N/A
Vulnerability Type
N/A