QID 980483
QID 980483: Nodejs (npm) Security Update for @fast-csv/parse (GHSA-8cv5-p934-3hwp)
Security update has been released for @fast-csv/parse,fast-csv to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Possible ReDoS (Regular Expression Denial of Service) when using `ignoreEmpty` option when parsing.
Solution
This has been patched in `v4.3.6`Workaround:
You will only be affected by this if you use the `ignoreEmpty` parsing option. If you do use this option it is recommended that you upgrade to the latest version `v4.3.6`
You will only be affected by this if you use the `ignoreEmpty` parsing option. If you do use this option it is recommended that you upgrade to the latest version `v4.3.6`
Vendor References
- GHSA-8cv5-p934-3hwp -
github.com/advisories/GHSA-8cv5-p934-3hwp
CVEs related to QID 980483
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8cv5-p934-3hwp | @fast-csv/parse |
|
|
| GHSA-8cv5-p934-3hwp | fast-csv |
|