Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29688
HistoryMar 15, 2021 - 1:24 a.m.

Regular Expression Denial Of Service (ReDoS)

2021-03-1501:24:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.002 Low

EPSS

Percentile

64.6%

ssri is vulnerable to regular expression denial of service. An attacker is able to crash the application by submitting a malicious string when the Integrity metadata is using the strict option. This results in a long processing time which would lead to the application crash.