Asymmetric denial of service In minimatch
Description
Regular Expression Denial of Service in minimatch
Affected versions of minimatch are vulnerable to regular expression denial of service attacks when user input is passed into the pattern argument of minimatch(path, pattern).
Proof of Concept
var minimatch = require(“minimatch”); // utility function for generating long strings var genstr = function (len, chr) { var result = “”; for (i=0; i<=len; i++) { result = result + chr; }...
Recommendation
Update to version 3.0.2 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 3.0.2 | ||
debian 11 | 3.0.3-1 | ||
debian 12 | 3.0.3-1 | ||
debian 13 | 3.0.3-1 | ||
debian 14 | 3.0.3-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1.