HIGH7.5
GHSA-832h-xg76-4gv6
ReDoS in brace-expansion
Quick fix
GHSA-832h-xg76-4gv6 — brace-expansion: upgrade to the fixed version with the command below.
npm install brace-expansion@1.1.7Details
Affected versions of `brace-expansion` are vulnerable to a regular expression denial of service condition.
## Proof of Concept
``` var expand = require('brace-expansion'); expand('{,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,\n}'); ```
## Recommendation
Update to version 1.1.7 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-18077[ADVISORY]
- https://github.com/juliangruber/brace-expansion/issues/33[WEB]
- https://github.com/juliangruber/brace-expansion/pull/35[WEB]
- https://github.com/juliangruber/brace-expansion/pull/35/commits/b13381281cead487cbdbfd6a69fb097ea5e456c3[WEB]
- https://bugs.debian.org/862712[WEB]
- https://github.com/advisories/GHSA-832h-xg76-4gv6[ADVISORY]
- https://github.com/juliangruber/brace-expansion[PACKAGE]
- https://www.npmjs.com/advisories/338[WEB]