MEDIUM5.9
GHSA-325j-24f4-qv5x
Regular Expression Denial of Service in ssri
Quick fix
GHSA-325j-24f4-qv5x — ssri: upgrade to the fixed version with the command below.
npm install ssri@5.2.2Details
Version of `ssri` prior to 5.2.2 are vulnerable to regular expression denial of service (ReDoS) when using strict mode.
## Recommendation
Update to version 5.2.2 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-7651[ADVISORY]
- https://github.com/zkat/ssri/issues/10[WEB]
- https://github.com/zkat/ssri/commit/d0ebcdc22cb5c8f47f89716d08b3518b2485d65d[WEB]
- https://github.com/advisories/GHSA-325j-24f4-qv5x[ADVISORY]
- https://github.com/zkat/ssri[PACKAGE]
- https://www.npmjs.com/advisories/565[WEB]