QID 981400

QID 981400: Nodejs (npm) Security Update for ssri (GHSA-325j-24f4-qv5x)

Version of `ssri` prior to 5.2.2 are vulnerable to regular expression denial of service (ReDoS) when using strict mode.


## Recommendation

Update to version 5.2.2 or later.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-325j-24f4-qv5x for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981400

    Software Advisories
    Advisory ID Software Component Link
    GHSA-325j-24f4-qv5x ssri URL Logo github.com/advisories/GHSA-325j-24f4-qv5x