Описание
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
Ссылки
- Broken Link
- Broken Link
- Broken Link
- Patch
- PatchVendor Advisory
- ExploitPatchThird Party Advisory
- Broken Link
- Broken Link
- Broken Link
- Patch
- PatchVendor Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
5.3 Medium
CVSS3
7.5 High
CVSS3
Дефекты
Связанные уязвимости
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
Versions of the package semver before 7.5.2 are vulnerable to Regular ...
semver vulnerable to Regular Expression Denial of Service
EPSS
5.3 Medium
CVSS3
7.5 High
CVSS3