{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-13762",
        "assignerOrgId": "1a37b84a-8e51-4525-b3d6-87e2fae01dbd",
        "state": "PUBLISHED",
        "assignerShortName": "GovTech CSG",
        "dateReserved": "2025-11-27T02:49:11.941Z",
        "datePublished": "2025-11-27T02:50:03.874Z",
        "dateUpdated": "2025-12-03T16:25:21.056Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "platforms": [
                        "Chrome",
                        "Edge"
                    ],
                    "product": "CyberArk Secure Web Sessions Extension",
                    "vendor": "CyberArk",
                    "versions": [
                        {
                            "lessThan": "2.2.30305",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Benjamen Lim"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Goh Jing Loon"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Sean Seah"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Tan Inn Fung"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Zhang Bosen"
                }
            ],
            "datePublic": "2025-11-27T02:49:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.<p>This issue affects CyberArk Secure Web Sessions Extension: before 2.2.30305.</p>"
                        }
                    ],
                    "value": "Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: before 2.2.30305."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-469",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-469 HTTP DoS"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "YES",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "attackVector": "LOCAL",
                        "baseScore": 4.8,
                        "baseSeverity": "MEDIUM",
                        "exploitMaturity": "ATTACKED",
                        "privilegesRequired": "NONE",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "subIntegrityImpact": "NONE",
                        "userInteraction": "PASSIVE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:A/AU:Y",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "LOW",
                        "vulnConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "NONE",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-20",
                            "description": "CWE-20 Improper Input Validation",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "1a37b84a-8e51-4525-b3d6-87e2fae01dbd",
                "shortName": "GovTech CSG",
                "dateUpdated": "2025-11-27T06:03:49.612Z"
            },
            "references": [
                {
                    "url": "https://chromewebstore.google.com/detail/cyberark-secure-web-sessi/ohfinlfcbaehgokpmkjcmkgdcbgamgln?hl=en"
                },
                {
                    "url": "https://microsoftedge.microsoft.com/addons/detail/cyberark-secure-web-sessi/gmfjibhpaliafbemoifjjdkmgaknhohb?hl=en-US"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<span style=\"background-color: rgb(255, 255, 255);\">Update SWS extension to v2.2.30305 or newer</span>\n\n<br>"
                        }
                    ],
                    "value": "Update SWS extension to v2.2.30305 or newer"
                }
            ],
            "source": {
                "discovery": "INTERNAL"
            },
            "title": "Client-Side Denial of Service Condition in SWS Extension prior to version 2.2.30305",
            "x_generator": {
                "engine": "Vulnogram 0.5.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-12-03T16:25:14.720836Z",
                                "id": "CVE-2025-13762",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-12-03T16:25:21.056Z"
                }
            }
        ]
    }
}