HIGH
GHSA-h6ch-v84p-w6p9
Regular Expression Denial of Service (ReDoS)
Quick fix
GHSA-h6ch-v84p-w6p9 — diff: upgrade to the fixed version with the command below.
npm install diff@3.5.0Details
A vulnerability was found in diff before v3.5.0, the affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/kpdecker/jsdiff/commit/2aec4298639bf30fb88a00b356bf404d3551b8c0[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1552148[WEB]
- https://snyk.io/vuln/npm:diff:20180305[WEB]
- https://www.npmjs.com/advisories/1631[WEB]
- https://www.whitesourcesoftware.com/vulnerability-database/WS-2018-0590[WEB]