CVE-2020-7755
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 27, 2020
Updated: Jan 7, 2025
CWE ID 400
Summary
CVE-2020-7755 represents a vulnerability in all versions of the dat.gui package. This issue allows an attacker to trigger a Regular Expression Denial of Service (ReDoS) attack through the manipulation of specific rgb and rgba values. ReDoS attacks consume significant computational resources, leading to a denial of service condition. Developers are strongly advised to update their implementations of dat.gui to address this vulnerability and protect against potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.