Описание
The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable under certain conditions.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:riot.js:riot-compiler:2.3.21:*:*:*:*:node.js:*:*
EPSS
Процентиль: 56%
0.00334
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-400
CWE-399
Связанные уязвимости
CVSS3: 7.5
github
почти 7 лет назад
Regular Expression Denial of Service in riot-compiler
EPSS
Процентиль: 56%
0.00334
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-400
CWE-399