Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j377-2x76-558h

Опубликовано: 10 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Input Validation in is-email

is-email helps validate an email address. A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.

Пакеты

Наименование

is-email

npm
Затронутые версииВерсия исправления

< 1.0.1

1.0.1

EPSS

Процентиль: 64%
0.00468
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.

EPSS

Процентиль: 64%
0.00468
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-400