Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-23364

Опубликовано: 28 апр. 2021
Источник: debian

Описание

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-browserslistfixed4.16.3+~cs5.4.72-2package
node-browserslistignoredbusterpackage

Примечания

  • https://github.com/browserslist/browserslist/commit/c091916910dfe0b5fd61caad96083c6709b02d98

  • https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194

  • https://github.com/browserslist/browserslist/pull/593

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

CVSS3: 5.3
redhat
почти 5 лет назад

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

CVSS3: 5.3
nvd
почти 5 лет назад

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

CVSS3: 5.3
github
больше 4 лет назад

Regular Expression Denial of Service in browserslist