HIGH7.5
GHSA-xmc8-cjfr-phx3
Regular Expression Denial of Service in highcharts
Quick fix
GHSA-xmc8-cjfr-phx3 — highcharts: upgrade to the fixed version with the command below.
npm install highcharts@6.1.0Details
Versions of `highcharts` prior to 6.1.0 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service.
## Recommendation
Upgrade to version 6.1.0 or higher.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-20801[ADVISORY]
- https://github.com/highcharts/highcharts/commit/7c547e1e0f5e4379f94396efd559a566668c0dfa[WEB]
- https://github.com/advisories/GHSA-xmc8-cjfr-phx3[ADVISORY]
- https://github.com/highcharts/highcharts[PACKAGE]
- https://security.netapp.com/advisory/ntap-20190715-0001[WEB]
- https://snyk.io/vuln/npm:highcharts:20180225[WEB]
- https://www.npmjs.com/advisories/793[WEB]