The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.
2021-03-23T17:15:14.027
2024-11-21T05:51:34.637
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | npmjs | hosted-git-info | < 2.8.9 | Yes |
Application | npmjs | hosted-git-info | < 3.0.8 | Yes |
Application | siemens | sinec_infrastructure_network_services | < 1.0.1.1 | Yes |