CVE-2020-28469
HIGH7.5EPSS 0.96%glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex
Published: 6/7/2021Modified: 4/28/2026
Description
This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.
Affected packages (3)
- Bitnami/gulpfrom 0, < 5.1.2
- Debian/node-glob-parentfrom 0, < 5.1.1+~5.1.0-2
- npm/glob-parent>= 4.0.0, < 5.1.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (12)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-28469
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-28469
- PATCHhttps://github.com/gulpjs/glob-parent
- WEBhttps://github.com/gulpjs/glob-parent/blob/6ce8d11f2f1ed8e80a9526b1dc8cf3aa71f43474/index.js%23L9
- WEBhttps://github.com/gulpjs/glob-parent/commit/4a80667c69355c76a572a5892b0f133c8e1f457e
- WEBhttps://github.com/gulpjs/glob-parent/pull/36
- WEBhttps://github.com/gulpjs/glob-parent/pull/36/commits/c6db86422a9731d4f3d332ce4a81c27ea6b0ee46
- WEBhttps://github.com/gulpjs/glob-parent/releases/tag/v5.1.2
- WEBhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBES128-1059093
- WEBhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1059092
- WEBhttps://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905
- WEBhttps://www.oracle.com/security-alerts/cpujan2022.html