Investigate NODE-4297 - upgrade kerberos dependency to use only ansi-regex ^6.0.1 due to Security Vulnerability

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Done
    • Priority: Unknown
    • None
    • Affects Version/s: None
    • Component/s: None
    • 1
    • None
    • Not Needed
    • None
    • None
    • None
    • None
    • None
    • None

      NODE-4297 Description

      Summary

      Security Vulnerabilities in kerberos 2.0.0

      This vulnerability comes from ansi-regex@2.1.1, which is a transitive dependency.
      the solution is to upgrade depndency 

      Motivation

      How does this affect the end user?

      Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to the sub-patterns{{ [\\]()#;?}} and (?:;[-a-zA-Z\\d\\/#&.:=?%@~_])*.

      Is this issue urgent?

      yes, possible ReDoS

       

       

      https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3807

              Assignee:
              Daria Pardue
              Reporter:
              TPM Jira Automations Bot
              None
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: