Описание
Regular expression denial of service in semver-regex
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
Пакеты
Наименование
semver-regex
npm
Затронутые версииВерсия исправления
< 3.1.4
3.1.4
Наименование
semver-regex
npm
Затронутые версииВерсия исправления
>= 4.0.0, < 4.0.3
4.0.3
Связанные уязвимости
CVSS3: 5.9
nvd
больше 3 лет назад
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method