Vulnerabilities/

Node-Redis potential exponential regex in monitor mode

Severity:
High

Description

When a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service.

Recommendation

Update the redis package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
redis
Anything's wrong? Let us know Last updated on January 29, 2023

This issue is available in SmartScanner Professional

See Pricing