You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There is vulnerability with CVE CVSS 3 severity of high/critical 7.5 level:
The semver package is vulnerable to Regular expression Denial of Service (ReDoS). Multiple functions and files listed below, fail to properly sanitize the range argument being provided by the user. An attacker, in some cases, can provide crafted inputs containing multiple whitespaces in the range, which when parsed by the package causes the regex engine to take longer, leading to a Denial of Service (DoS) condition.
Please ASAP upgrade semver to 7.5.2
There is vulnerability with CVE CVSS 3 severity of high/critical 7.5 level:
The semver package is vulnerable to Regular expression Denial of Service (ReDoS). Multiple functions and files listed below, fail to properly sanitize the range argument being provided by the user. An attacker, in some cases, can provide crafted inputs containing multiple whitespaces in the range, which when parsed by the package causes the regex engine to take longer, leading to a Denial of Service (DoS) condition.
More information is available in https://nvd.nist.gov/vuln/detail/CVE-2022-25883
The text was updated successfully, but these errors were encountered: