CVE-2018-7651

index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ssri_project:ssri:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 04:12

Type Values Removed Values Added
References () https://github.com/zkat/ssri/commit/d0ebcdc22cb5c8f47f89716d08b3518b2485d65d - Patch, Third Party Advisory () https://github.com/zkat/ssri/commit/d0ebcdc22cb5c8f47f89716d08b3518b2485d65d - Patch, Third Party Advisory
References () https://github.com/zkat/ssri/issues/10 - Third Party Advisory () https://github.com/zkat/ssri/issues/10 - Third Party Advisory
References () https://nodesecurity.io/advisories/565 - Third Party Advisory () https://nodesecurity.io/advisories/565 - Third Party Advisory

Information

Published : 2018-03-04 01:29

Updated : 2024-11-21 04:12


NVD link : CVE-2018-7651

Mitre link : CVE-2018-7651

CVE.ORG link : CVE-2018-7651


JSON object : View

Products Affected

ssri_project

  • ssri
CWE
CWE-400

Uncontrolled Resource Consumption