Описание
Regular Expression Denial of Service
A Regular Expression Denial of Service vulnerability was discovered in esm before 3.1.0. The issue is that esm's find-indexes is using the unescaped identifiers in a regex, which, in this case, causes an infinite loop.
Пакеты
Наименование
esm
npm
Затронутые версииВерсия исправления
< 3.1.0
3.1.0
Дефекты
CWE-400
Дефекты
CWE-400