Executive brief
string-kit is a JavaScript library for string manipulation commonly used in Node.js applications. The naturalSort function contains an inefficient regular expression that can be exploited to cause excessive CPU consumption and denial of service. An unauthenticated attacker can send specially crafted strings to any application using the vulnerable library, causing the application to freeze or crash.
Technical details
This is a ReDoS (Regular Expression Denial of Service) vulnerability in the naturalSort() function of string-kit versions up to 0.12.7. The vulnerable function used a poorly optimized regular expression that could exhibit catastrophic backtracking when processing specially crafted input strings. The vulnerability is remotely exploitable without authentication or special privileges. An attacker can trigger excessive CPU consumption by providing malicious input to the naturalSort function, leading to application slowdown or complete unavailability. Version 0.12.8 addresses this issue by rewriting the naturalSort function to eliminate the vulnerable regex entirely, replacing it with direct string matching logic.
Affected products
- cronvel string-kit up to 0.12.7
Timeline
- 2023-01-02: disclosed
- 2021-08-17: patched: Version 0.12.8 released with fix
- 2023-01-04: advisory: GitHub reviewed advisory