Inefficient Regular Expression Complexity in chalk/ansi-regex #333
Labels
Auto Create Issues
Label for Auto Created Issues
High
This label for Security Severity only
Security
Label for Security Issues
Milestone
Description
ansi-regex is vulnerable to Inefficient Regular Expression Complexity which could lead to a denial of service.
Severity Check
Severity Number
7.5 / 10
CVSS base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-697 CWE-1333
CVE ID
CVE-2021-3807
GHSA ID
GHSA-93q8-gq69-wqmw
Source code
chalk/ansi-regex
Information
Package
ansi-regex (npm)
Affected versions
6.0.1
5.0.1
4.1.1
3.0.1
References
https://nvd.nist.gov/vuln/detail/CVE-2021-3807
chalk/ansi-regex@8d1d7cd
https://huntr.dev/bounties/5b3cf33b-ede0-4398-9974-800876dfd994
Backport of security patch, for benefit of yargs chalk/ansi-regex#38 (comment)
https://app.snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
Backport of security patch, for benefit of yargs chalk/ansi-regex#38 (comment)
https://github.com/chalk/ansi-regex/releases/tag/v6.0.1
https://www.oracle.com/security-alerts/cpuapr2022.html
https://security.netapp.com/advisory/ntap-20221014-0002/
chalk/ansi-regex@419250f
chalk/ansi-regex@75a657d
chalk/ansi-regex@c3c0b3f
The text was updated successfully, but these errors were encountered: