QID 982590
QID 982590: Nodejs (npm) Security Update for is-svg (GHSA-7r28-3m3f-r2pr)
The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7r28-3m3f-r2pr for updates pertaining to this vulnerability.
Vendor References
- GHSA-7r28-3m3f-r2pr -
github.com/advisories/GHSA-7r28-3m3f-r2pr
CVEs related to QID 982590
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7r28-3m3f-r2pr | is-svg |
|