QID 983768
QID 983768: Nodejs (npm) Security Update for is-my-json-valid (GHSA-f522-ffg8-j8r6)
Version of `is-my-json-valid` before 1.4.1 or 2.17.2 are vulnerable to regular expression denial of service (ReDoS) via the email validation function. ## Recommendation Update to version 1.4.1, 2.17.2 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-f522-ffg8-j8r6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-f522-ffg8-j8r6 -
github.com/advisories/GHSA-f522-ffg8-j8r6
CVEs related to QID 983768
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f522-ffg8-j8r6 | is-my-json-valid |
|