CVE-2021-43307
02.06.2022, 14:15
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() methodEnginsight
Vendor | Product | Version |
---|---|---|
semver-regex_project | semver-regex | 𝑥 < 3.1.4 |
semver-regex_project | semver-regex | 4.0.0 ≤ 𝑥 < 4.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration