Description
The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0928 | The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity. |
Github GHSA |
GHSA-43f8-2h32-f4cj | Regular Expression Denial of Service in hosted-git-info |
Ubuntu USN |
USN-5216-1 | hosted-git-info vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-17T03:02:03.337Z
Reserved: 2021-01-08T00:00:00.000Z
Link: CVE-2021-23362
No data.
Status : Modified
Published: 2021-03-23T17:15:14.027
Modified: 2024-11-21T05:51:34.637
Link: CVE-2021-23362
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN