Toot

Written by bEA 🔓 on 2024-10-25 at 18:49

ReDoS (Regular Expression Denial of Service) being High severity in MITRE is such a crock of shit.

@yossarian wrote about this 2 years ago, and it's just as true today. MITRE acts like they're paid per CVE, and they're desperate for pocket money. The wrong people have been incentivised for the wrong things.

A DoS of a library/application should not be a High. A DoS of an OS or appliance could maybe be a High!

https://blog.yossarian.net/2022/12/28/ReDoS-vulnerabilities-and-misaligned-incentives

=> More informations about this toot | View the thread | More toots from bea@infosec.exchange

Mentions

=> View yossarian@infosec.exchange profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113369557864937397
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
232.953725 milliseconds
Gemini-to-HTML Time
0.320046 milliseconds

This content has been proxied by September (ba2dc).