Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-26256

Опубликовано: 08 дек. 2020
Источник: nvd
CVSS3: 5.7
CVSS3: 6.5
CVSS2: 3.5
EPSS Низкий

Описание

Fast-csv is an npm package for parsing and formatting CSVs or any other delimited value file in node. In fast-cvs before version 4.3.6 there is a possible ReDoS vulnerability (Regular Expression Denial of Service) when using ignoreEmpty option when parsing. This has been patched in v4.3.6 You will only be affected by this if you use the ignoreEmpty parsing option. If you do use this option it is recommended that you upgrade to the latest version v4.3.6 This vulnerability was found using a CodeQL query which identified EMPTY_ROW_REGEXP regular expression as vulnerable.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:c2fo:fast-csv:*:*:*:*:*:node.js:*:*
Версия до 4.3.6 (исключая)

EPSS

Процентиль: 77%
0.01073
Низкий

5.7 Medium

CVSS3

6.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-400
CWE-400

Связанные уязвимости

CVSS3: 5.7
github
около 5 лет назад

Denial of service in fast-csv

EPSS

Процентиль: 77%
0.01073
Низкий

5.7 Medium

CVSS3

6.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-400
CWE-400