GHSA-4gmj-3p3h-gm8h
es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`
Quick fix
GHSA-4gmj-3p3h-gm8h — es5-ext: upgrade to the fixed version with the command below.
npm install es5-ext@0.10.63Details
### Impact
Passing functions with very long names or complex default argument names into `function#copy` or`function#toStringTokens` may put script to stall
### Patches Fixed with https://github.com/medikoo/es5-ext/commit/3551cdd7b2db08b1632841f819d008757d28e8e2 and https://github.com/medikoo/es5-ext/commit/a52e95736690ad1d465ebcd9791d54570e294602 Published with v0.10.63
### Workarounds No real workaround aside of refraining from using above utilities.
### References https://github.com/medikoo/es5-ext/issues/201
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/medikoo/es5-ext/security/advisories/GHSA-4gmj-3p3h-gm8h[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-27088[ADVISORY]
- https://github.com/medikoo/es5-ext/issues/201[WEB]
- https://github.com/medikoo/es5-ext/commit/3551cdd7b2db08b1632841f819d008757d28e8e2[WEB]
- https://github.com/medikoo/es5-ext/commit/a52e95736690ad1d465ebcd9791d54570e294602[WEB]
- https://github.com/medikoo/es5-ext[PACKAGE]