Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-23362
HistoryMar 23, 2021 - 5:15 p.m.

Design/Logic Flaw

2021-03-2317:15:00
PRIOn knowledge base
www.prio-n.com
8

6 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.9%

The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.