Описание
This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.1 (исключая)
cpe:2.3:a:npmjs:npm-user-validate:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 81%
0.0163
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.5
redhat
больше 4 лет назад
This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.
CVSS3: 7.5
github
около 4 лет назад
Regular expression denial of service in npm-user-validate
CVSS3: 7.5
fstec
больше 4 лет назад
Уязвимость пакета npm-user-validate програмной платформы node.js, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
Процентиль: 81%
0.0163
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
NVD-CWE-noinfo