Lucene search

K
nodejsCristian-Alexandru StaicuNODEJS:526
HistorySep 08, 2017 - 8:23 p.m.

Regular Expression Denial of Service

2017-09-0820:23:54
Cristian-Alexandru Staicu
www.npmjs.com
21

0.001 Low

EPSS

Percentile

44.7%

Overview

Affected versions of fresh are vulnerable to regular expression denial of service when parsing specially crafted user input.

Recommendation

Update to version 0.5.2 or later.

References

GitHub Advisory

CPENameOperatorVersion
freshlt 0.5.2