CVE Vulnerabilities

CVE-2021-27293

Incorrect Comparison

Published: Jul 12, 2021 | Modified: Sep 09, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp will be stuck processing it for an exceedingly long time. Thus the remote server can trigger Denial of Service.

Weakness

The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Restsharp Restsharp * 106.11.7 (including)
Restsharp Restsharp 106.11.8-alpha0.10 (including) 106.11.8-alpha0.10 (including)
Restsharp Restsharp 106.11.8-alpha0.11 (including) 106.11.8-alpha0.11 (including)
Restsharp Restsharp 106.11.8-alpha0.12 (including) 106.11.8-alpha0.12 (including)
Restsharp Restsharp 106.11.8-alpha0.2 (including) 106.11.8-alpha0.2 (including)
Restsharp Restsharp 106.11.8-alpha0.3 (including) 106.11.8-alpha0.3 (including)
Restsharp Restsharp 106.11.8-alpha0.4 (including) 106.11.8-alpha0.4 (including)
Restsharp Restsharp 106.11.8-alpha0.6 (including) 106.11.8-alpha0.6 (including)
Restsharp Restsharp 106.11.8-alpha0.7 (including) 106.11.8-alpha0.7 (including)

Extended Description

This Pillar covers several possibilities:

References