Asymmetric denial of service In node-glob-parent
Description
glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 5.1.1+~5.1.0-2 | ||
debian 12 | 5.1.1+~5.1.0-2 | ||
debian 14 | 5.1.1+~5.1.0-2 | ||
debian 13 | 5.1.1+~5.1.0-2 | ||
npm | 5.1.2 | ||
rpm rhel8.4 | 1:14.18.2-2.module+el8.4.0+13643+6c0ebf22 | ||
rpm rhel9 | 0:2.0.19-1.el9_0 | ||
rpm rhel8 | 1:14.18.2-2.module+el8.5.0+13644+8d46dafd | ||
rpm rhel8 | - | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6.