Vulnerabilities/

string-kit Inefficient Regular Expression Complexity vulnerability

Severity:
High

Description

A vulnerability classified as problematic was found in cronvel string-kit up to 0.12.7. This vulnerability affects the function naturalSort of the file lib/naturalSort.js. The manipulation leads to inefficient regular expression complexity. The attack can be initiated remotely. Upgrading to version 0.12.8 can address this issue.

Recommendation

Update the string-kit package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
string-kit
Anything's wrong? Let us know Last updated on February 03, 2023

This issue is available in SmartScanner Professional

See Pricing