logo

CVE-2018-20801 highcharts

Package

Manager: npm
Name: highcharts
Vulnerable Version: >=0 <6.1.0

Severity

Level: High

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.01321 pctl0.7911

Details

Regular Expression Denial of Service in highcharts Versions of `highcharts` prior to 6.1.0 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service. ## Recommendation Upgrade to version 6.1.0 or higher.

Metadata

Created: 2019-03-18T15:59:32Z
Modified: 2021-09-21T22:36:57Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-xmc8-cjfr-phx3/GHSA-xmc8-cjfr-phx3.json
CWE IDs: ["CWE-1333"]
Alternative ID: GHSA-xmc8-cjfr-phx3
Finding: F211
Auto approve: 1