QID 981135
QID 981135: Nodejs (npm) Security Update for uglify-js (GHSA-c9f4-xj24-8jqx)
Versions of `uglify-js` prior to 2.6.0 are affected by a regular expression denial of service vulnerability when malicious inputs are passed into the `parse()` method.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c9f4-xj24-8jqx for updates pertaining to this vulnerability.
Vendor References
- GHSA-c9f4-xj24-8jqx -
github.com/advisories/GHSA-c9f4-xj24-8jqx
CVEs related to QID 981135
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c9f4-xj24-8jqx | uglify-js |
|