QID 981963
QID 981963: Nodejs (npm) Security Update for csv-parse (GHSA-582f-p4pg-xc74)
Versions of `csv-parse` prior to 4.4.6 are vulnerable to Regular Expression Denial of Service. The `__isInt()` function contains a malformed regular expression that processes large specially-crafted input very slowly, leading to a Denial of Service. This is triggered when using the `cast` option.
## Recommendation
Upgrade to version 4.4.6 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-582f-p4pg-xc74 for updates pertaining to this vulnerability.
Vendor References
- GHSA-582f-p4pg-xc74 -
github.com/advisories/GHSA-582f-p4pg-xc74
CVEs related to QID 981963
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-582f-p4pg-xc74 | csv-parse |
|