QID 980799
QID 980799: Nodejs (npm) Security Update for semver (GHSA-x6fg-f45m-jf5q)
Versions 4.3.1 and earlier of `semver` are affected by a regular expression denial of service vulnerability when extremely long version strings are parsed.
## Recommendation
Update to version 4.3.2 or later
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x6fg-f45m-jf5q for updates pertaining to this vulnerability.
Vendor References
- GHSA-x6fg-f45m-jf5q -
github.com/advisories/GHSA-x6fg-f45m-jf5q
CVEs related to QID 980799
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x6fg-f45m-jf5q | semver |
|