Vulnerability Report
Description:
In security alerts, dependabot is reporting a moderate priority vulnerability.
- semver vulnerable to Regular Expression Denial of Service
Impact:
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
Some regular expression engines have a feature called "backtracking". If the token cannot match, the engine "backtracks" to a position that may result in a different token that can match.
Backtracking becomes a weakness if all of these conditions are met:
- The number of possible backtracking attempts are exponential relative to the length of the input.
- The input can fail to match the regular expression.
- The input can be long enough.
Attackers can create crafted inputs that intentionally cause the regular expression to use excessive backtracking in a way that causes the CPU consumption to spike.
Proposed Solution:
Update the library semver from v5.3.0 to v7.5.4 (latest until August 11th/2023). Pull Request
Affected Version:
Vulnerability Report
Description:
In security alerts, dependabot is reporting a moderate priority vulnerability.
Impact:
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
Some regular expression engines have a feature called "backtracking". If the token cannot match, the engine "backtracks" to a position that may result in a different token that can match.
Backtracking becomes a weakness if all of these conditions are met:
Attackers can create crafted inputs that intentionally cause the regular expression to use excessive backtracking in a way that causes the CPU consumption to spike.
Proposed Solution:
Update the library
semverfrom v5.3.0 to v7.5.4 (latest until August 11th/2023). Pull RequestAffected Version: