Опубликовано: 04 мар. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.9
Описание
index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | DNE | |
| bionic | ignored | end of standard support, was needs-triage |
| cosmic | ignored | end of life |
| devel | not-affected | 5.2.4-2 |
| disco | not-affected | 5.2.4-2 |
| eoan | not-affected | 5.2.4-2 |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | not-affected | 5.2.4-2 |
| esm-apps/jammy | not-affected | 5.2.4-2 |
| esm-apps/noble | not-affected | 5.2.4-2 |
Показывать по
10
EPSS
Процентиль: 76%
0.01754
Низкий
4.3 Medium
CVSS2
5.9 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.9
nvd
больше 8 лет назад
index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.
CVSS3: 5.9
debian
больше 8 лет назад
index.js in the ssri module before 5.2.2 for Node.js is prone to a reg ...
EPSS
Процентиль: 76%
0.01754
Низкий
4.3 Medium
CVSS2
5.9 Medium
CVSS3