QID 983494
QID 983494: Nodejs (npm) Security Update for is-my-json-valid (GHSA-ccq6-3qx5-vmqx)
Withdrawn, accidental duplicate publish.
The is-my-json-valid package before 2.12.4 for Node.js has an incorrect exports['utc-millisec'] regular expression, which allows remote attackers to cause a denial of service (blocked event loop) via a crafted string.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-ccq6-3qx5-vmqx for updates pertaining to this vulnerability.
Vendor References
- GHSA-ccq6-3qx5-vmqx -
github.com/advisories/GHSA-ccq6-3qx5-vmqx
CVEs related to QID 983494
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ccq6-3qx5-vmqx | is-my-json-valid |
|