CVE-2018-20801 – highcharts
Package
Manager: npm
Name: highcharts
Vulnerable Version: >=0 <6.1.0
Severity
Level: High
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.01321 pctl0.7911
Details
Regular Expression Denial of Service in highcharts Versions of `highcharts` prior to 6.1.0 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service. ## Recommendation Upgrade to version 6.1.0 or higher.
Metadata
Created: 2019-03-18T15:59:32Z
Modified: 2021-09-21T22:36:57Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-xmc8-cjfr-phx3/GHSA-xmc8-cjfr-phx3.json
CWE IDs: ["CWE-1333"]
Alternative ID: GHSA-xmc8-cjfr-phx3
Finding: F211
Auto approve: 1