Uploaded image for project: 'Node.js Driver'
  1. Node.js Driver
  2. NODE-4297

upgrade kerberos dependency to use only ansi-regex ^6.0.1 due to Security Vulnerability

    • Type: Icon: Task Task
    • Resolution: Done
    • Priority: Icon: Unknown Unknown
    • kerberos-2.0.1
    • Affects Version/s: kerberos-1.1.7, kerberos-2.0.0
    • Component/s: None
    • Labels:
    • 2
    • Not Needed

      Summary

      Security Vulnerabilities in kerberos 2.0.0

      This vulnerability comes from ansi-regex@2.1.1, which is a transitive dependency.
      the solution is to upgrade depndency 

      Motivation

      How does this affect the end user?

      Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to the sub-patterns{{ [\\]()#;?}} and (?:;[-a-zA-Z\\d\\/#&.:=?%@~_])*.

      Is this issue urgent?

      yes, possible ReDoS

       

       

      https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3807

        There are no Sub-Tasks for this issue.

            Assignee:
            neal.beeken@mongodb.com Neal Beeken
            Reporter:
            moscovih@post.bgu.ac.il Hadas Moscovici
            Neal Beeken
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved: