Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7mwh-4pqv-wmr8

Опубликовано: 02 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Regular expression denial of service in scss-tokenizer

All versions of the package scss-tokenizer prior to 0.4.3 are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

Пакеты

Наименование

scss-tokenizer

npm
Затронутые версииВерсия исправления

<= 0.4.2

0.4.3

EPSS

Процентиль: 65%
0.00493
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

CVSS3: 5.3
redhat
больше 3 лет назад

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

CVSS3: 5.3
nvd
больше 3 лет назад

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

CVSS3: 5.3
debian
больше 3 лет назад

All versions of package scss-tokenizer are vulnerable to Regular Expre ...

EPSS

Процентиль: 65%
0.00493
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333