Lucene search

K
osvGoogleOSV:CVE-2021-23362
HistoryMar 23, 2021 - 5:15 p.m.

CVE-2021-23362

2021-03-2317:15:14
Google
osv.dev
5

6.5 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.8%

The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.