Executive brief
Switcher Client is a JavaScript library used for feature flagging and configuration management. A flaw in how the library processes strategy matching operations allows an attacker to craft specially-formed input that causes the application's regular expression engine to consume excessive CPU resources, rendering the service unavailable.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) attack in the Strategy match operation when using EXIST or NOT_EXIST logic operations. Unsanitized input is directly incorporated into regular expression construction without validation, allowing an attacker to supply input that triggers exponential backtracking in the regex engine. The attack is network-accessible and requires no authentication or user interaction. An attacker can cause denial of service by exhausting CPU resources. The vulnerability is patched in version 3.1.4.
Affected products
- Switcher API Switcher Client < 3.1.4
Timeline
- 2023-02-02: disclosed
- 2023-02-02: patched: Fixed in version 3.1.4