CVE-2020-7754
Summary
| CVE | CVE-2020-7754 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-27 15:15:00 UTC |
| Updated | 2020-10-27 17:31:00 UTC |
| Description | This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Npmjs | Npm-user-validate | All | All | All | All |
| Application | Npmjs | Npm-user-validate | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Regular Expression Denial of Service (ReDoS) in org.webjars.npm:npm-user-validate | Snyk | CONFIRM | snyk.io | Exploit, Third Party Advisory |
| Regular Expression Denial of Service in npm-user-validate · Advisory · npm/npm-user-validate · GitHub | CONFIRM | github.com | Third Party Advisory |
| fix: update email validation · npm/npm-user-validate@c8a87da · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Regular Expression Denial of Service (ReDoS) in npm-user-validate | Snyk | CONFIRM | snyk.io | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Yeting Li
Legacy QID Mappings
- 377388 Alibaba Cloud Linux Security Update for nodejs:14 (ALINUX3-SA-2021:0016)
- 940231 AlmaLinux Security Update for nodejs:10 (ALSA-2021:0548)
- 940253 AlmaLinux Security Update for nodejs:12 (ALSA-2021:0549)
- 940254 AlmaLinux Security Update for nodejs:14 (ALSA-2021:0551)
- 960749 Rocky Linux Security Update for nodejs:14 (RLSA-2021:0551)
- 960803 Rocky Linux Security Update for nodejs:12 (RLSA-2021:0549)
- 960843 Rocky Linux Security Update for nodejs:10 (RLSA-2021:0548)
- 982611 Nodejs (npm) Security Update for npm-user-validate (GHSA-pw54-mh39-w3hc)