Description
The npm package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity
Recommendation
Update the hosted-git-info package to the latest compatible version. Followings are version details:
Affected version(s): **< 2.8.9 >= 3.0.0, < 3.0.8** Patched version(s): **2.8.9 3.0.8**
References
Could your website be exposed too?
SmartScanner can check your website for Regular Expression Denial of Service in hosted-git-info and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-image - CVE-2021-21391
- Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-font - CVE-2021-21391
- Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-engine - CVE-2021-21391
- Regular expression Denial of Service in @progfay/scrapbox-parser - CVE-2021-27405


