Security Advisory

CVE-2021-23362

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-03-23 16:20:14
Last updated 2024-09-17 03:02:03
Assigner snyk
CVSS score 5.3
State PUBLISHED

Description

The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.