Asymmetric denial of service - ReDoS In semver-regex
Description
Affected versions of this package are vulnerable to Regular Expression Denial of Service due to improper usage of regex in the semverRegex() function.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 3.1.4, 4.0.3 | ||
maven | - |
Aliases
1. 2. 3. 4. 5.
References
1. 2.