-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Inefficient Regular Expression Complexity vulnerability pending CVSS allocation #921
Comments
I have no idea what you're referring to. Please give me some more information. There have been a few ReDos vulnerabilities found that have taken one of two outcomes: a CVE has been allocated, or a CVE has been explicitly blocked and the researcher was asked not to take it further because the surface area was negligible except under the most egregious, irresponsible uses of the library. For example, in one case, you would have had to have passed long, unsanitized user input into the namespace parameter of the It's the same thing as when we received a "vulnerability" report in At this point, ReDos reports against this package are being considered spam and I've been reporting them to Huntr in most cases when they come through. I'm not sure where you're seeing this information but I doubt whatever "report" you're seeing actually affects you. |
To be abundantly clear, there has never been a reported ReDos attack using Whatever report you're seeing there has not been responsibly reported to me at all. I'm unaware of any pending security report against that version of |
I'm using JetBrains tools, specifically WebStrom, but it should be any of them. The reason for mentioning it here was that I did not find it listed in any way. Also, others may ask, so hopefully this helps asking the same question or multiple reports. This is the link it takes you too
I'm not saying it is an issue. I hope this helps.
So, it looks like considered spam. Maybe put this up front, pin it, or add to the README so others won't ask. |
Closing as a dupe of #924 (aware it was posted after this issue, however it has more details and a linked investigation with more pertinent information about the filing). Thanks for bringing this to my attention. |
Dependency npm:debug:4.3.4 is vulnerable Cx8bc4df28-fcf5 7.5 Inefficient Regular Expression Complexity vulnerability pending CVSS allocation Results powered by Checkmarx(c)
Is this being looked into or resolved?
The text was updated successfully, but these errors were encountered: