Infinite loop Affecting codeigniter4/framework package, versions <4.4.7


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-CODEIGNITER4FRAMEWORK-6514871
  • published1 Apr 2024
  • disclosed29 Mar 2024
  • creditCole Thorsen

Introduced: 29 Mar 2024

CVE-2024-29904  (opens in a new tab)
CWE-835  (opens in a new tab)

How to fix?

Upgrade codeigniter4/framework to version 4.4.7 or higher.

Overview

codeigniter4/framework is a PHP full-stack web framework that is light, fast, flexible, and secure.

Affected versions of this package are vulnerable to Infinite loop that allows attackers to consume a large amount of memory by passing invalid characters to the Language class's lang() function.

Workaround

One attack vector for this vulnerability can be avoided by disabling Auto Routing.

References

CVSS Scores

version 3.1