Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hj48-42vr-x3v9

Опубликовано: 10 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Regular Expression Denial of Service in path-parse

Affected versions of npm package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.

Пакеты

Наименование

path-parse

npm
Затронутые версииВерсия исправления

< 1.0.7

1.0.7

EPSS

Процентиль: 65%
0.00506
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
redhat
около 4 лет назад

All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.

CVSS3: 5.3
nvd
около 4 лет назад

All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.

rocky
больше 3 лет назад

Important: nodejs:14 security and bug fix update

suse-cvrf
больше 3 лет назад

Security update for nodejs14

suse-cvrf
больше 3 лет назад

Security update for nodejs8

EPSS

Процентиль: 65%
0.00506
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400