debricked / soot-wrapper

Analyses how you use your dependencies to figure out if you use the vulnerable parts of a vulnerable dependency
MIT License
4 stars 5 forks source link

A new vulnerability was discovered: CVE-2021-27290 #35

Closed debricked[bot] closed 2 years ago

debricked[bot] commented 3 years ago

ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

Read more at Debricked: https://app.debricked.com/en/service/vulnerability/211870