QID 980342
QID 980342: Nodejs (npm) Security Update for ssri (GHSA-vx3p-948g-6vhq)
npm `ssri` 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vx3p-948g-6vhq for updates pertaining to this vulnerability.
Vendor References
- GHSA-vx3p-948g-6vhq -
github.com/advisories/GHSA-vx3p-948g-6vhq
CVEs related to QID 980342
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vx3p-948g-6vhq | ssri |
|