QID 984024
QID 984024: Nodejs (npm) Security Update for parsejson (GHSA-q75g-2496-mxpp)
Affected versions of `parsejson` are vulnerable to a regular expression denial of service when parsing untrusted user input. ## Recommendation The `parsejson` package has not been functionally updated since it was initially released. Additionally, it provides functionality which is natively included in Node.js, and therefore the native `JSON.parse()` should be used, for both performance and security reasons.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q75g-2496-mxpp for updates pertaining to this vulnerability.
Vendor References
- GHSA-q75g-2496-mxpp -
github.com/advisories/GHSA-q75g-2496-mxpp
CVEs related to QID 984024
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q75g-2496-mxpp | parsejson |
|