Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
2023-06-21T05:15:09.060
2024-12-06T17:15:07.260
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | npmjs | semver | < 5.7.2 | Yes |
Application | npmjs | semver | < 6.3.1 | Yes |
Application | npmjs | semver | < 7.5.2 | Yes |