CVE-2021-29059
21.06.2021, 16:15
A vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a crafted invalid SVG string.Enginsight
Vendor | Product | Version |
---|---|---|
is-svg_project | is-svg | 2.1.0 ≤ 𝑥 < 4.3.0 |
𝑥
= Vulnerable software versions
References