Vulnerabilities/

Regular Expression Denial of Service in ssri

Severity:
Medium

Description

Version of ssri prior to 5.2.2 are vulnerable to regular expression denial of service (ReDoS) when using strict mode.

Recommendation

Update the ssri package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ssri
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing