CVE-2020-26304 – foundation-sites
Package
Manager: npm
Name: foundation-sites
Vulnerable Version: >=0 <=6.3.3
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
EPSS: 0.00207 pctl0.43204
Details
Foundation Regular Expression Denial of Service vulnerability Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available.
Metadata
Created: 2024-10-26T21:30:46Z
Modified: 2024-11-13T23:24:36Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-p8pc-3f7w-jr5q/GHSA-p8pc-3f7w-jr5q.json
CWE IDs: ["CWE-1333"]
Alternative ID: GHSA-p8pc-3f7w-jr5q
Finding: F211
Auto approve: 1