HIGH7.5
GHSA-vx3p-948g-6vhq
Regular Expression Denial of Service (ReDoS)
Quick fix
GHSA-vx3p-948g-6vhq — ssri: upgrade to the fixed version with the command below.
npm install ssri@6.0.2Details
npm `ssri` 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-27290[ADVISORY]
- https://github.com/npm/ssri/pull/20#issuecomment-842677644[WEB]
- https://github.com/npm/ssri/commit/76e223317d971f19e4db8191865bdad5edee40d2[WEB]
- https://github.com/npm/ssri/commit/809c84d09ea87c3857fa171d42914586899d4538[WEB]
- https://github.com/npm/ssri/commit/b30dfdb00bb94ddc49a25a85a18fb27afafdfbb1[WEB]
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf[WEB]
- https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf[WEB]
- https://github.com/npm/ssri[PACKAGE]
- https://github.com/yetingli/SaveResults/blob/main/pdf/ssri-redos.pdf[WEB]
- https://npmjs.com[WEB]
- https://www.npmjs.com/package/ssri[WEB]
- https://www.oracle.com/security-alerts/cpuoct2021.html[WEB]