Описание
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
Ссылки
- Broken Link
- PatchThird Party Advisory
- Third Party Advisory
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Broken Link
- PatchThird Party Advisory
- Third Party Advisory
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0.0 (включая) до 4.16.5 (исключая)
cpe:2.3:a:browserslist_project:browserslist:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 59%
0.00385
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-1333
Связанные уязвимости
CVSS3: 5.3
ubuntu
почти 5 лет назад
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
CVSS3: 5.3
redhat
почти 5 лет назад
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
CVSS3: 5.3
debian
почти 5 лет назад
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable t ...
CVSS3: 5.3
github
больше 4 лет назад
Regular Expression Denial of Service in browserslist
EPSS
Процентиль: 59%
0.00385
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-1333