Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTMyNWotMjRmNC1xdjV4
Regular Expression Denial of Service in ssri
Version of ssri
prior to 5.2.2 are vulnerable to regular expression denial of service (ReDoS) when using strict mode.
Recommendation
Update to version 5.2.2 or later.
Permalink: https://github.com/advisories/GHSA-325j-24f4-qv5xJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTMyNWotMjRmNC1xdjV4
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 7 years ago
Updated: almost 2 years ago
CVSS Score: 5.9
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Percentage: 0.00202
EPSS Percentile: 0.58508
Identifiers: GHSA-325j-24f4-qv5x, CVE-2018-7651
References:
- https://nvd.nist.gov/vuln/detail/CVE-2018-7651
- https://github.com/advisories/GHSA-325j-24f4-qv5x
- https://www.npmjs.com/advisories/565
- https://github.com/zkat/ssri/issues/10
- https://github.com/zkat/ssri/commit/d0ebcdc22cb5c8f47f89716d08b3518b2485d65d
Blast Radius: 35.3
Affected Packages
npm:ssri
Dependent packages: 838Dependent repositories: 951,034
Downloads: 119,294,923 last month
Affected Version Ranges: < 5.2.2
Fixed in: 5.2.2
All affected versions: 0.0.0, 1.0.0, 2.0.0, 3.0.0, 3.0.1, 3.0.2, 4.0.0, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, 4.1.6, 5.0.0, 5.1.0, 5.2.1
All unaffected versions: 5.2.2, 5.2.3, 5.2.4, 5.3.0, 6.0.0, 6.0.1, 6.0.2, 7.0.0, 7.0.1, 7.1.0, 7.1.1, 8.0.0, 8.0.1, 9.0.0, 9.0.1, 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, 10.0.5, 10.0.6, 11.0.0, 12.0.0