CVE-2021-23362
23.03.2021, 17:15
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.Enginsight
Vendor | Product | Version |
---|---|---|
npmjs | hosted-git-info | 2.0.0 ≤ 𝑥 < 2.8.9 |
npmjs | hosted-git-info | 3.0.0 ≤ 𝑥 < 3.0.8 |
siemens | sinec_infrastructure_network_services | 𝑥 < 1.0.1.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References