Description
The package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.
Recommendation
Update the handsontable package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.0.0
- Patched version(s): 10.0.0
References
Related Issues
- axios Inefficient Regular Expression Complexity vulnerability - CVE-2021-3749
- Inefficient Regular Expression Complexity in validator.js - CVE-2021-3765
- Inefficient Regular Expression Complexity in vuelidate - CVE-2021-3794
- string-kit Inefficient Regular Expression Complexity vulnerability - CVE-2021-4299
- Tags:
- npm
- handsontable
Anything's wrong? Let us know Last updated on September 05, 2023