Описание
index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.2.2 (исключая)
cpe:2.3:a:ssri_project:ssri:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 59%
0.00377
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-400
Связанные уязвимости
CVSS3: 5.9
ubuntu
почти 8 лет назад
index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.
CVSS3: 5.9
debian
почти 8 лет назад
index.js in the ssri module before 5.2.2 for Node.js is prone to a reg ...
EPSS
Процентиль: 59%
0.00377
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-400