Vulnerabilities/

Denial of Service in foreman

Severity:
High

Description

All versions of foreman are vulnerable to Regular Expression Denial of Service when requests to it are made with a specially crafted path.

Recommendation

Update the foreman package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
foreman
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing