Vulnerabilities/

jsx-slack insufficient patch for CVE-2021-43838 ReDoS

Severity:
Medium

Description

We found the patch for CVE-2021-43838 in jsx-slack v4.5.1 is insufficient to save from Regular Expression Denial of Service (ReDoS) attack.

This vulnerability affects to jsx-slack v4.5.1 and earlier versions.

Recommendation

Update the jsx-slack package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jsx-slack
Anything's wrong? Let us know Last updated on January 30, 2023

This issue is available in SmartScanner Professional

See Pricing