-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
securityA security or vulnerability issueA security or vulnerability issue
Description
Package: cross-spawn
Current Version: 7.0.3
Fixed Version: 7.0.5, 6.0.6
Severity: HIGH
Description:
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
References:
- https://access.redhat.com/security/cve/CVE-2024-21538
- https://github.com/moxystudio/node-cross-spawn
- moxystudio/node-cross-spawn@5ff3a07
- moxystudio/node-cross-spawn@640d391
- moxystudio/node-cross-spawn@d35c865
- Backport GHSA-3xgq-45jj-v275 moxystudio/node-cross-spawn#165
- fix: disable regexp backtracking moxystudio/node-cross-spawn#160
- https://nvd.nist.gov/vuln/detail/CVE-2024-21538
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-8366349
- https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230
- https://www.cve.org/CVERecord?id=CVE-2024-21538
Metadata
Metadata
Assignees
Labels
securityA security or vulnerability issueA security or vulnerability issue