Описание
ReDoS in brace-expansion
Affected versions of brace-expansion are vulnerable to a regular expression denial of service condition.
Proof of Concept
Recommendation
Update to version 1.1.7 or later.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-18077
- https://github.com/juliangruber/brace-expansion/issues/33
- https://github.com/juliangruber/brace-expansion/pull/35
- https://github.com/juliangruber/brace-expansion/pull/35/commits/b13381281cead487cbdbfd6a69fb097ea5e456c3
- https://bugs.debian.org/862712
- https://github.com/advisories/GHSA-832h-xg76-4gv6
- https://www.npmjs.com/advisories/338
Пакеты
brace-expansion
< 1.1.7
1.1.7
Связанные уязвимости
index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.
index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.
index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.
index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expr ...