CVE-2021-23343
04.05.2021, 09:15
All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.Enginsight
Vendor | Product | Version |
---|---|---|
path-parse_project | path-parse | 𝑥 < 1.0.7 |
𝑥
= Vulnerable software versions
References