CVE-2021-27290

HIGH7.5EPSS 2.5%

Regular Expression Denial of Service (ReDoS)

發布日:2021/3/19修改日:2023/11/8
也稱為:GHSA-vx3p-948g-6vhqALPINE-CVE-2021-27290

描述

npm `ssri` 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

參考連結(14)