Описание
The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."
Ссылки
- Mailing ListThird Party Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkExploitMitigationVendor Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkExploitMitigationVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.7.1 (исключая)
cpe:2.3:a:vercel:ms:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 76%
0.00944
Низкий
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-1333
CWE-1333
Связанные уязвимости
redhat
больше 10 лет назад
The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."
CVSS3: 7.5
debian
около 9 лет назад
The ms package before 0.7.1 for Node.js allows attackers to cause a de ...
EPSS
Процентиль: 76%
0.00944
Низкий
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-1333
CWE-1333