Lucene search

K
cvelistHackeroneCVELIST:CVE-2016-10540
HistoryApr 26, 2018 - 12:00 a.m.

CVE-2016-10540

2018-04-2600:00:00
CWE-400
hackerone
www.cve.org
2

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.0%

Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript RegExp objects. The primary function, minimatch(path, pattern) in Minimatch 3.0.1 and earlier is vulnerable to ReDoS in the pattern parameter.

CNA Affected

[
  {
    "product": "minimatch node module",
    "vendor": "HackerOne",
    "versions": [
      {
        "status": "affected",
        "version": "<=3.0.1"
      }
    ]
  }
]

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.0%