Логотип exploitDog
bind:CVE-2021-28092
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-28092

Количество 3

Количество 3

redhat логотип

CVE-2021-28092

почти 5 лет назад

The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-28092

почти 5 лет назад

The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7r28-3m3f-r2pr

почти 5 лет назад

Regular Expression Denial of Service (ReDoS)

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2021-28092

The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-28092

The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-7r28-3m3f-r2pr

Regular Expression Denial of Service (ReDoS)

CVSS3: 7.5
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу