HIGH7.5
GHSA-ww39-953v-wcq6
glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex
Quick fix
GHSA-ww39-953v-wcq6 — glob-parent: upgrade to the fixed version with the command below.
npm install glob-parent@5.1.2Details
This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-28469[ADVISORY]
- https://github.com/gulpjs/glob-parent/pull/36[WEB]
- https://github.com/gulpjs/glob-parent/pull/36/commits/c6db86422a9731d4f3d332ce4a81c27ea6b0ee46[WEB]
- https://github.com/gulpjs/glob-parent/commit/4a80667c69355c76a572a5892b0f133c8e1f457e[WEB]
- https://github.com/gulpjs/glob-parent[PACKAGE]
- https://github.com/gulpjs/glob-parent/blob/6ce8d11f2f1ed8e80a9526b1dc8cf3aa71f43474/index.js%23L9[WEB]
- https://github.com/gulpjs/glob-parent/releases/tag/v5.1.2[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBES128-1059093[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1059092[WEB]
- https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905[WEB]
- https://www.oracle.com/security-alerts/cpujan2022.html[WEB]