Description
The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3247-1 | node-trim-newlines security update |
EUVD |
EUVD-2021-1281 | The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method. |
Github GHSA |
GHSA-7p7h-4mm5-852v | Uncontrolled Resource Consumption in trim-newlines |
Ubuntu USN |
USN-5999-1 | trim-newlines vulnerability |
References
History
Sun, 08 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.4::el8 |
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:58:21.580Z
Reserved: 2021-05-28T00:00:00.000Z
Link: CVE-2021-33623
No data.
Status : Modified
Published: 2021-05-28T18:15:07.537
Modified: 2024-11-21T06:09:12.880
Link: CVE-2021-33623
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN