Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-25883


Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.


Published

2023-06-21T05:15:09.060

Last Modified

2024-12-06T17:15:07.260

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-1333
  • Type: Primary
    CWE-1333
  • Type: Secondary
    CWE-1333

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application npmjs semver < 5.7.2 Yes
Application npmjs semver < 6.3.1 Yes
Application npmjs semver < 7.5.2 Yes

References