QID 980583
QID 980583: Nodejs (npm) Security Update for jsoneditor (GHSA-hhfg-6hfc-rvxm)
The jsoneditor package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted element as input to the getInnerText function may cause an application to consume an excessive amount of CPU. Below pinned line using vulnerable regex.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hhfg-6hfc-rvxm for updates pertaining to this vulnerability.
Vendor References
- GHSA-hhfg-6hfc-rvxm -
github.com/advisories/GHSA-hhfg-6hfc-rvxm
CVEs related to QID 980583
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hhfg-6hfc-rvxm | jsoneditor |
|