{"id":"GHSA-v78m-2q7v-fjqp","summary":"Uncontrolled Recursion in rulex","details":"### Impact\nWhen parsing untrusted rulex expressions, the stack may overflow, possibly enabling a Denial of Service attack. This happens when parsing an expression with several hundred levels of nesting, causing the process to abort immediately.\n\nThis is a security concern for you, if\n- your service parses untrusted rulex expressions (expressions provided by an untrusted user), and\n- your service becomes unavailable when the process running rulex aborts due to a stack overflow.\n\n### Patches\nThe crash is fixed in version **0.4.3**. Affected users are advised to update to this version.\n\n### Workarounds\nNone.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [rulex](https://github.com/rulex-rs/rulex/issues)\n* Email me at [ludwig.stecher@gmx.de](mailto:ludwig.stecher@gmx.de)\n\n### Credits\n\nCredit for finding these bugs goes to\n\n- [evanrichter](https://github.com/evanrichter)\n- [ForAllSecure Mayhem](https://forallsecure.com/)\n- [cargo fuzz](https://github.com/rust-fuzz/cargo-fuzz) and [afl.rs](https://github.com/rust-fuzz/afl.rs)","aliases":["CVE-2022-31099","RUSTSEC-2022-0030"],"modified":"2023-11-08T04:09:25.959683Z","published":"2022-06-22T17:52:51Z","database_specific":{"nvd_published_at":"2022-06-27T23:15:00Z","cwe_ids":["CWE-674"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-06-22T17:52:51Z"},"references":[{"type":"WEB","url":"https://github.com/rulex-rs/rulex/security/advisories/GHSA-v78m-2q7v-fjqp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31099"},{"type":"WEB","url":"https://github.com/rulex-rs/rulex/commit/60aa2dc03a22d69c8800fec81f99c96958a11363"},{"type":"PACKAGE","url":"https://github.com/rulex-rs/rulex"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0030.html"}],"affected":[{"package":{"name":"rulex","ecosystem":"crates.io","purl":"pkg:cargo/rulex"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-v78m-2q7v-fjqp/GHSA-v78m-2q7v-fjqp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}