Lack of data validation In aws-lambda-multipart-parser
Description
AWS Lambda parser is vulnerable to Regular Expression Denial of Service index.js in the aws-lambda-multipart-parser NPM package before 0.1.2 has a Regular Expression Denial of Service (ReDoS) issue via a crafted multipart/form-data boundary string.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 0.1.2 |
Aliases
1. 2. 3. 4. 5.
References
1.