Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9fhw-r42p-5c7r

Опубликовано: 01 мар. 2021
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Regular expression Denial of Service in @progfay/scrapbox-parser

Impact

A Regular expression Denial of Service flaw was found in the @progfay/scrapbox-parser package before 6.0.3, 7.0.2 for Node.js. The attacker that is able to be parsed a specially crafted text may cause the application to consume an excessive amount of CPU.

Patches

Upgrade to version 6.0.3, 7.0.2 or later.

Workarounds

Avoid to parse text with a lot of [ chars.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

@progfay/scrapbox-parser

npm
Затронутые версииВерсия исправления

< 6.0.3

6.0.3

Наименование

@progfay/scrapbox-parser

npm
Затронутые версииВерсия исправления

>= 7.0.0, < 7.0.2

7.0.2

EPSS

Процентиль: 68%
0.00563
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for Node.js.

EPSS

Процентиль: 68%
0.00563
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400