-
Type:
Task
-
Resolution: Done
-
Priority:
Unknown
-
Affects Version/s: kerberos-1.1.7, kerberos-2.0.0
-
Component/s: None
Summary
Security Vulnerabilities in kerberos 2.0.0
This vulnerability comes from ansi-regex@2.1.1, which is a transitive dependency.
the solution is to upgrade depndency
Motivation
How does this affect the end user?
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to the sub-patterns{{ [\\]()#;?}} and (?:;[-a-zA-Z\\d\\/#&.:=?%@~_])*.
Is this issue urgent?
yes, possible ReDoS
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3807
- depends on
-
NODE-4298 Investigate NODE-4297 - upgrade kerberos dependency to use only ansi-regex ^6.0.1 due to Security Vulnerability
-
- Closed
-
There are no Sub-Tasks for this issue.