Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-77002
HistoryJun 09, 2022 - 12:00 a.m.

npm Devcert Denial of Service Vulnerability

2022-06-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
4

0.001 Low

EPSS

Percentile

36.8%

Devcert is a package for SSL development from npm, Inc. A denial of service vulnerability exists in versions prior to Devcert 1.2.1, which stems from triggering an exponential ReDoS (regular expression denial of service) in the Devcert package. An attacker could exploit this vulnerability to cause a denial of service of the application.

CPENameOperatorVersion
npm devcertlt1.2.1

0.001 Low

EPSS

Percentile

36.8%