Описание
Denial of Service in rgb2hex
All versions of rgb2hex are vulnerable to Regular Expression Denial of Service (ReDoS) when an attacker can pass in a specially crafted invalid color value.
Recommendation
Update to version 0.1.6 or later.
Пакеты
Наименование
rgb2hex
npm
Затронутые версииВерсия исправления
< 0.1.6
0.1.6
6.5 Medium
CVSS3
Дефекты
CWE-400
6.5 Medium
CVSS3
Дефекты
CWE-400