Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8qv-6jwh-64r5

Опубликовано: 24 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Regular Expression Denial of Service in browserslist

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

Пакеты

Наименование

browserslist

npm
Затронутые версииВерсия исправления

>= 4.0.0, < 4.16.5

4.16.5

EPSS

Процентиль: 59%
0.00385
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1333
CWE-400

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

CVSS3: 5.3
redhat
почти 5 лет назад

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

CVSS3: 5.3
nvd
почти 5 лет назад

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

CVSS3: 5.3
debian
почти 5 лет назад

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable t ...

EPSS

Процентиль: 59%
0.00385
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1333
CWE-400