Description
The npm package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity
Recommendation
Update the hosted-git-info package to the latest compatible version. Followings are version details:
Affected version(s): **< 2.8.9 >= 3.0.0, < 3.0.8** Patched version(s): **2.8.9 3.0.8**
References
Related Issues
- Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-image - CVE-2021-21391
- Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-font - CVE-2021-21391
- Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-engine - CVE-2021-21391
- Regular expression Denial of Service in @progfay/scrapbox-parser - CVE-2021-27405
You might also like:
- Tags:
- npm
- hosted-git-info
Anything's wrong? Let us know Last updated on February 01, 2023


