High severityNVD Advisory· Published Feb 3, 2023· Updated Mar 10, 2025
Switcher Client contains Regular Expression Denial of Service (ReDoS)
CVE-2023-23925
Description
Switcher Client is a JavaScript SDK to work with Switcher API which is cloud-based Feature Flag. Unsanitized input flows into Strategy match operation (EXIST), where it is used to build a regular expression. This may result in a Regular expression Denial of Service attack (reDOS). This issue has been patched in version 3.1.4. As a workaround, avoid using Strategy settings that use REGEX in conjunction with EXIST and NOT_EXIST operations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
switcher-clientnpm | < 3.1.4 | 3.1.4 |
Affected products
2- switcherapi/switcher-client-masterv5Range: < 3.1.4
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-wqxw-8h5g-hq56ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-23925ghsaADVISORY
- github.com/switcherapi/switcher-client-master/commit/374752563d6ce9353ee592b40c809c8136f24930ghsaWEB
- github.com/switcherapi/switcher-client-master/releases/tag/v3.1.4ghsax_refsource_MISCWEB
- github.com/switcherapi/switcher-client-master/security/advisories/GHSA-wqxw-8h5g-hq56ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.