Junglewise Threat Intelligence

CVE-2023-23925: Switcher Client regular expression denial of service

CVE-2023-23925 · Severity: low · CVSS 3.1 · Published 2023-02-02

Vendors: npm.

Executive brief

Switcher Client is a JavaScript library used for feature flagging and configuration management. A flaw in how the library processes strategy matching operations allows an attacker to craft specially-formed input that causes the application's regular expression engine to consume excessive CPU resources, rendering the service unavailable.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) attack in the Strategy match operation when using EXIST or NOT_EXIST logic operations. Unsanitized input is directly incorporated into regular expression construction without validation, allowing an attacker to supply input that triggers exponential backtracking in the regex engine. The attack is network-accessible and requires no authentication or user interaction. An attacker can cause denial of service by exhausting CPU resources. The vulnerability is patched in version 3.1.4.

Affected products

  • Switcher API Switcher Client < 3.1.4

Timeline

  • 2023-02-02: disclosed
  • 2023-02-02: patched: Fixed in version 3.1.4

References