itsKedar / TodoList_mern

0 stars 0 forks source link

CX: Cx8bc4df28-fcf5 in Npm-debug and 3.2.7 @ TodoList_mern.main #7

Open itsKedar opened 2 years ago

itsKedar commented 2 years ago

Description

In NPM debug, the enable function accepts a regular expression from user input without escaping it. Arbitrary regular expressions could be injected to cause a Denial of Service attack on the user's browser, otherwise known as a ReDoS (Regular Expression Denial of Service). This is a different issue than CVE-2017-16137.

HIGH Vulnerable Package issue exists @ debug in branch main

Vulnerability ID: Cx8bc4df28-fcf5

Package Name: debug

Severity: HIGH

CVSS Score: 7.5

Publish Date: 2020-12-10T17:14:00

Current Package Version: 3.2.7

Remediation Upgrade Recommendation:

Link To SCA

itsKedar commented 2 years ago

Issue still exists.

itsKedar commented 2 years ago

Issue still exists.

itsKedar commented 2 years ago

Issue still exists.