Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3xgq-45jj-v275

Опубликовано: 08 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

Regular Expression Denial of Service (ReDoS) in cross-spawn

Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

Пакеты

Наименование

cross-spawn

npm
Затронутые версииВерсия исправления

>= 7.0.0, < 7.0.5

7.0.5

Наименование

cross-spawn

npm
Затронутые версииВерсия исправления

< 6.0.6

6.0.6

EPSS

Процентиль: 21%
0.00067
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 4.4
redhat
около 1 года назад

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

CVSS3: 7.5
nvd
около 1 года назад

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

CVSS3: 7.5
msrc
около 1 года назад

Описание отсутствует

suse-cvrf
около 1 года назад

Security update for nodejs18

suse-cvrf
около 1 года назад

Security update for nodejs20

EPSS

Процентиль: 21%
0.00067
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-1333