MEDIUM 6.5 Maven

Navigate endpoint is vulnerable to regex injection that may lead to Denial of Service.

GHSA-hf44-3mx6-vhhw · CVE-2021-29506

Published · Modified

Description

Impact

The regex injection that may lead to Denial of Service.

Patches

Will be patched in 2.4 and 3.0

Workarounds

Versions lower than 2.x are only affected if the navigation module is added

References

See this pull request for the fix: https://github.com/graphhopper/graphhopper/pull/2304

If you have any questions or comments about this advisory please send us an Email or create a topic here.

Ready to move

Start Securing

Free, no credit card | First findings in minutes