HIGH7.5
GHSA-xfhp-gmh8-r8v2
printf vulnerable to Regular Expression Denial of Service (ReDoS)
Quick fix
GHSA-xfhp-gmh8-r8v2 — printf: upgrade to the fixed version with the command below.
npm install printf@0.6.1Details
The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string ```regex /\%(?:\(([\w_.]+)\)|([1-9]\d*)\$)?([0 +\-\]*)(\*|\d+)?(\.)?(\*|\d+)?[hlL]?([\%bscdeEfFgGioOuxX])/g ``` in `lib/printf.js`. The vulnerable regular expression has cubic worst-case time complexity.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23354[ADVISORY]
- https://github.com/adaltas/node-printf/issues/31[WEB]
- https://github.com/adaltas/node-printf/pull/32[WEB]
- https://github.com/adaltas/node-printf/commit/a8502e7c9b0b22555696a2d8ef67722086413a68[WEB]
- https://snyk.io/vuln/SNYK-JS-PRINTF-1072096[WEB]