Vulnerabilities/

d3-color vulnerable to ReDoS

Severity:
High

Description

The d3-color module provides representations for various color spaces in the browser. Versions prior to 3.1.0 are vulnerable to a Regular expression Denial of Service. This issue has been patched in version 3.1.0. There are no known workarounds.

Recommendation

Update the d3-color package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
d3-color
Anything's wrong? Let us know Last updated on January 13, 2023

This issue is available in SmartScanner Professional

See Pricing