Open
Description
Please ASAP upgrade semver to 7.5.2
There is vulnerability with CVE CVSS 3 severity of high/critical 7.5 level:
The semver package is vulnerable to Regular expression Denial of Service (ReDoS). Multiple functions and files listed below, fail to properly sanitize the range argument being provided by the user. An attacker, in some cases, can provide crafted inputs containing multiple whitespaces in the range, which when parsed by the package causes the regex engine to take longer, leading to a Denial of Service (DoS) condition.
More information is available in https://nvd.nist.gov/vuln/detail/CVE-2022-25883
Metadata
Metadata
Assignees
Labels
No labels