Intelligence View
⚡ tsecurity.de Intelligence
CVE-2018-1109 | Braces up to 2.3.0 on npm incorrect regex
A vulnerability, which was classified as critical, was found in Braces up to 2.3.0 on npm. This impacts an unknown function. Such manipulation leads to…
A vulnerability, which was classified as critical, was found in Braces up to 2.3.0 on npm. This impacts an unknown function. Such manipulation leads to incorrect regular expression.
This vulnerability is referenced as CVE-2018-1109. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
This vulnerability is referenced as CVE-2018-1109. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
Cyber Threat Intelligence & Forensik
Bedrohungsgraph · ATT&CK-Mapping · Exploit-Belege
IoC Intelligence
1 Indikatoren · Defanged · STIX 2.1
CVE-2018-1109
Exploit & Remediation Lifecycle
PoC · Ausnutzung · Patch-Stufen
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Bislang kein öffentlicher Exploit
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & PoC Radar
Nur belegte Faktoren · kein Score-Theater
Exploit-DB
Kein EDB-EintragInteraktion
Interaktion nötigAuthentifizierung
ErforderlichCompliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
Advisory Radar
Offizielles Hersteller-Update verfügbar
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Red Hat Security Bulletin Verifiziertredhat.com
-
Web Referencesnyk.io