QID 980342

QID 980342: Nodejs (npm) Security Update for ssri (GHSA-vx3p-948g-6vhq)

npm `ssri` 5.2.2-6.0.1 and 7.0.0-8.0.0, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-vx3p-948g-6vhq for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980342

    Software Advisories
    Advisory ID Software Component Link
    GHSA-vx3p-948g-6vhq ssri URL Logo github.com/advisories/GHSA-vx3p-948g-6vhq