GHSA-g95f-p29q-9xw4 – braces
Package
Manager: npm
Name: braces
Vulnerable Version: >=0 <2.3.1
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
EPSS: N/A pctlN/A
Details
Regular Expression Denial of Service in braces Versions of `braces` prior to 2.3.1 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service. ## Recommendation Upgrade to version 2.3.1 or higher.
Metadata
Created: 2019-06-06T15:30:30Z
Modified: 2021-08-04T21:35:07Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-g95f-p29q-9xw4/GHSA-g95f-p29q-9xw4.json
CWE IDs: ["CWE-185", "CWE-400"]
Alternative ID: N/A
Finding: F211
Auto approve: 1