Executive brief
StealJS, a popular JavaScript dependency loader, is vulnerable to a denial-of-service attack. An attacker can provide specially crafted input that causes the software to consume excessive processing power, potentially crashing the application or making it unresponsive to legitimate users. This impact can disrupt web services and business operations that rely on this library for loading code.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in StealJS versions up to and including 2.3.0. The flaw is located within the 'source' and 'sourceWithComments' variables in 'main.js', where inefficient regular expressions can be triggered by malicious input. An unauthenticated remote attacker can exploit this by providing a crafted string that causes catastrophic backtracking during regex evaluation. This leads to high CPU utilization and a denial-of-service condition. As of the advisory publication, users are advised to review their use of the library and check for updates from the maintainers.
Affected products
- stealjs steal <= 2.3.0
Timeline
- 2022-09-14: disclosed: Issue reported on GitHub repository
- 2022-09-15: advisory: NVD published CVE-2022-37262
- 2022-09-16: advisory: GitHub Advisory published GHSA-28v4-jf82-jvj8