Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38844
HistoryJan 12, 2023 - 4:43 a.m.

Regular Expression Denial Of Service (ReDoS)

2023-01-1204:43:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
string-kit
redos
vulnerability
naturalsort.js
user-input
application crash

0.001 Low

EPSS

Percentile

48.0%

string-kit is vulnerable to regular expression denial of service attacks. The vulnerability exists via the module.exports function in naturalSort.js, which does not properly handle user-input data due to to inefficient regular expression complexity, allowing an attacker to cause an application crash.

CPENameOperatorVersion
string-kitle0.12.7
string-kitle0.12.7

0.001 Low

EPSS

Percentile

48.0%

Related for VERACODE:38844