Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jxqq-cqm6-pfq9

Опубликовано: 24 июл. 2018
Источник: github
Github: Прошло ревью

Описание

Regular Expression Denial of Service in slug

Affected versions of slug are vulnerable to a regular expression denial of service when parsing untrusted user input.

The issue is low severity, as it takes 50,000 characters to cause the event loop to block for 2 seconds,

About 50k characters can block the event loop for 2 seconds.

Recommendation

Update to version 0.9.2 or later.

Пакеты

Наименование

slug

npm
Затронутые версииВерсия исправления

<= 0.9.1

0.9.2

EPSS

Процентиль: 58%
0.00362
Низкий

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted untrusted input is passed as input. About 50k characters can block the event loop for 2 seconds.

EPSS

Процентиль: 58%
0.00362
Низкий

Дефекты

CWE-400