Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35840
HistoryJun 03, 2022 - 4:58 a.m.

Regular Expression Denial Of Service (ReDoS)

2022-06-0304:58:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.001 Low

EPSS

Percentile

36.8%

devcert is vulnerable to regular expression denial of service. An attacker can crash the application by providing a malicious input to the certificateFor function of index.ts due to the insecure regex pattern used for VALID_IP and VALID_DOMAIN parameters.

CPENameOperatorVersion
devcertle1.2.0
devcertle1.2.0

0.001 Low

EPSS

Percentile

36.8%

Related for VERACODE:35840