Asymmetric denial of service - ReDoS In devcert
Description
Regular expression denial of service in devcert An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 1.2.1 |
Aliases
1. 2. 3. 4.
References
1. 2.