Open dev-mend-for-github-com[bot] opened 5 months ago
System.Text.RegularExpressions
Library home page: https://api.nuget.org/packages/system.text.regularexpressions.4.3.0.nupkg
Path to vulnerable library: /NuGet_NonSDK_Project/packages/NSwag.MSBuild.11.8.2/build/NetCore10/System.Text.RegularExpressions.dll
Found in HEAD commit: 5afe80afda8dd921dae28a00290d896f12ac1ccf
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Dependency Hierarchy: - :x: **System.Text.RegularExpressions-4.6.24705.01.dll** (Vulnerable Library)
Found in base branch: main
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Publish Date: 2019-05-16
URL: CVE-2019-0820
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: N/A - Impact Metrics: - Confidentiality Impact: N/A - Integrity Impact: N/A - Availability Impact: N/A
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2019-0820
Release Date: 2019-05-16
Fix Resolution: LocaleWorks.Core - 0.1.1;GWallet.Backend - 0.2.15--date20210210-1105.git-2f5ecf0;KY.Generator - 8.0.0;dnx-coreclr-darwin-x64 - 1.0.0-rc1-final;dnx-coreclr-linux-x64 - 1.0.0-rc1-final;DataPumpCon - 1.0.1;JetBrains.ReSharper.CommandLineTools - 2021.2.1,2020.3.0,2020.2.0-eap01,2021.1.0-eap01,2020.3.0-eap05;dnx-coreclr-win-x64 - 1.0.0-rc1-final;dnx-coreclr-win-x86 - 1.0.0-rc1-final;CodeGeneration.Roslyn.BuildTime - 0.4.6;Fable.Compiler - 1.0.0-narumi-921;ResearchAPI - 2.0.0;NSwag.MSBuild - 13.4.0;Paket.SDK - 0.0.1-gamma01,0.0.1-beta2;com.nitrocrime.XamarinPainter - 0.1.1;Nuke.Common - 0.18.0-alpha0038,0.19.0;Nlog.RabbitMQ.Target - 2.5.1;FSharp.Data.Npgsql - 0.2.7-beta,0.1.42-beta;Dolittle.SDK.Build - 5.0.0-alpha.5;Codecov - 1.2.0;VL.CEF - 0.0.8-stride;ddplatform.ddrrBackendCommonUtils - 1.0.15-beta;JetBrains.ReSharper.GlobalTools - 2021.1.0-eap01,2020.2.0-eap01,2020.3.0,2021.2.1,2020.3.0-eap05;System.Text.RegularExpressions - 4.0.11-beta-23225;Sarif.Multitool - 2.0.0-csd.1;AspectInjector - 2.0.0-rc2;Peachpie.NET.Sdk - 1.0.0,1.0.0-preview4;TfsCmdlets - 2.0.0-beta0008;NBench.Runner - 1.1.0;NLog.RabbitMQ.Target - 2.5.4;Iride - 0.1.1;Cake.Tfs - 0.3.2-beta0001;Toolbelt.Blazor.I18nText - 10.0.0-preview.1,9.4.1;ExcelProvider - 2.0.0-rc1;tsqllint - 1.13.0;JetBrains.ReSharper.TestRunner.Adapters.NUnit3 - 2.6.1.37,1.2.7.18,1.2.9.24;Utf8Json - 1.0.0.1;Cake.CoreCLR - 0.26.0;Tocsoft.GraphQLCodeGen.MsBuild - 0.1.0-beta0015;WebApiClient.AOT - 0.0.6;Lazlo.Powershell.Operations - 1.2.1402;PathOfSupporting - 0.0.1-beta2;Nuke.CodeGeneration - 0.18.0-alpha0038,0.19.0;AspNetCore.Client.Generator - 0.4.1+76;Akka.MultiNodeTestRunner - 1.4.0-beta1;FaIndustry.RelaFax.RestManager - 1.0.2;WaveEngine.Targets - 3.2.0.7765-preview;NugetVersion - 1.0.3;Cake.Tfs.Build.Variables - 0.0.3;TestCentric.GuiRunner - 2.0.0-alpha1
Vulnerable Library - System.Text.RegularExpressions-4.6.24705.01.dll
System.Text.RegularExpressions
Library home page: https://api.nuget.org/packages/system.text.regularexpressions.4.3.0.nupkg
Path to vulnerable library: /NuGet_NonSDK_Project/packages/NSwag.MSBuild.11.8.2/build/NetCore10/System.Text.RegularExpressions.dll
Found in HEAD commit: 5afe80afda8dd921dae28a00290d896f12ac1ccf
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2019-0820
### Vulnerable Library - System.Text.RegularExpressions-4.6.24705.01.dllSystem.Text.RegularExpressions
Library home page: https://api.nuget.org/packages/system.text.regularexpressions.4.3.0.nupkg
Path to vulnerable library: /NuGet_NonSDK_Project/packages/NSwag.MSBuild.11.8.2/build/NetCore10/System.Text.RegularExpressions.dll
Dependency Hierarchy: - :x: **System.Text.RegularExpressions-4.6.24705.01.dll** (Vulnerable Library)
Found in HEAD commit: 5afe80afda8dd921dae28a00290d896f12ac1ccf
Found in base branch: main
### Vulnerability DetailsA denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Publish Date: 2019-05-16
URL: CVE-2019-0820
### CVSS 4 Score Details (8.7)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: N/A - Impact Metrics: - Confidentiality Impact: N/A - Integrity Impact: N/A - Availability Impact: N/A
For more information on CVSS4 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2019-0820
Release Date: 2019-05-16
Fix Resolution: LocaleWorks.Core - 0.1.1;GWallet.Backend - 0.2.15--date20210210-1105.git-2f5ecf0;KY.Generator - 8.0.0;dnx-coreclr-darwin-x64 - 1.0.0-rc1-final;dnx-coreclr-linux-x64 - 1.0.0-rc1-final;DataPumpCon - 1.0.1;JetBrains.ReSharper.CommandLineTools - 2021.2.1,2020.3.0,2020.2.0-eap01,2021.1.0-eap01,2020.3.0-eap05;dnx-coreclr-win-x64 - 1.0.0-rc1-final;dnx-coreclr-win-x86 - 1.0.0-rc1-final;CodeGeneration.Roslyn.BuildTime - 0.4.6;Fable.Compiler - 1.0.0-narumi-921;ResearchAPI - 2.0.0;NSwag.MSBuild - 13.4.0;Paket.SDK - 0.0.1-gamma01,0.0.1-beta2;com.nitrocrime.XamarinPainter - 0.1.1;Nuke.Common - 0.18.0-alpha0038,0.19.0;Nlog.RabbitMQ.Target - 2.5.1;FSharp.Data.Npgsql - 0.2.7-beta,0.1.42-beta;Dolittle.SDK.Build - 5.0.0-alpha.5;Codecov - 1.2.0;VL.CEF - 0.0.8-stride;ddplatform.ddrrBackendCommonUtils - 1.0.15-beta;JetBrains.ReSharper.GlobalTools - 2021.1.0-eap01,2020.2.0-eap01,2020.3.0,2021.2.1,2020.3.0-eap05;System.Text.RegularExpressions - 4.0.11-beta-23225;Sarif.Multitool - 2.0.0-csd.1;AspectInjector - 2.0.0-rc2;Peachpie.NET.Sdk - 1.0.0,1.0.0-preview4;TfsCmdlets - 2.0.0-beta0008;NBench.Runner - 1.1.0;NLog.RabbitMQ.Target - 2.5.4;Iride - 0.1.1;Cake.Tfs - 0.3.2-beta0001;Toolbelt.Blazor.I18nText - 10.0.0-preview.1,9.4.1;ExcelProvider - 2.0.0-rc1;tsqllint - 1.13.0;JetBrains.ReSharper.TestRunner.Adapters.NUnit3 - 2.6.1.37,1.2.7.18,1.2.9.24;Utf8Json - 1.0.0.1;Cake.CoreCLR - 0.26.0;Tocsoft.GraphQLCodeGen.MsBuild - 0.1.0-beta0015;WebApiClient.AOT - 0.0.6;Lazlo.Powershell.Operations - 1.2.1402;PathOfSupporting - 0.0.1-beta2;Nuke.CodeGeneration - 0.18.0-alpha0038,0.19.0;AspNetCore.Client.Generator - 0.4.1+76;Akka.MultiNodeTestRunner - 1.4.0-beta1;FaIndustry.RelaFax.RestManager - 1.0.2;WaveEngine.Targets - 3.2.0.7765-preview;NugetVersion - 1.0.3;Cake.Tfs.Build.Variables - 0.0.3;TestCentric.GuiRunner - 2.0.0-alpha1