-
Type:
Task
-
Resolution: Done
-
Priority:
Unknown
-
None
-
Affects Version/s: None
-
Component/s: None
NODE-4297 Description
Summary
Security Vulnerabilities in kerberos 2.0.0
This vulnerability comes from ansi-regex@2.1.1, which is a transitive dependency.
the solution is to upgrade depndency
Motivation
How does this affect the end user?
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to the sub-patterns{{ [\\]()#;?}} and (?:;[-a-zA-Z\\d\\/#&.:=?%@~_])*.
Is this issue urgent?
yes, possible ReDoS
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3807
- is depended on by
-
NODE-4297 upgrade kerberos dependency to use only ansi-regex ^6.0.1 due to Security Vulnerability
-
- Closed
-