Количество 2
Количество 2
CVE-2022-25918
больше 3 лет назад
The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.
CVSS3: 5.3
EPSS: Низкий
GHSA-cr84-xvw4-qx3c
больше 3 лет назад
Inefficient Regular Expression Complexity in shescape
CVSS3: 7.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-25918 The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-cr84-xvw4-qx3c Inefficient Regular Expression Complexity in shescape | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу
20