Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cgfm-xwp7-2cvr

Опубликовано: 31 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Sanitize-html Vulnerable To REDoS Attacks

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

Пакеты

Наименование

sanitize-html

npm
Затронутые версииВерсия исправления

< 2.7.1

2.7.1

EPSS

Процентиль: 18%
0.00058
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

CVSS3: 5.3
redhat
больше 3 лет назад

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

CVSS3: 5.3
nvd
больше 3 лет назад

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

CVSS3: 5.3
debian
больше 3 лет назад

The package sanitize-html before 2.7.1 are vulnerable to Regular Expre ...

EPSS

Процентиль: 18%
0.00058
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333