Regular expression Denial of Service in @progfay/scrapbox-parser
Moderate severity
GitHub Reviewed
Published
Feb 19, 2021
in
progfay/scrapbox-parser
•
Updated Feb 1, 2023
Package
Affected versions
< 6.0.3
>= 7.0.0, < 7.0.2
Patched versions
6.0.3
7.0.2
Description
Published by the National Vulnerability Database
Feb 19, 2021
Reviewed
Feb 26, 2021
Published to the GitHub Advisory Database
Mar 1, 2021
Last updated
Feb 1, 2023
Impact
A Regular expression Denial of Service flaw was found in the @progfay/scrapbox-parser package before 6.0.3, 7.0.2 for Node.js.
The attacker that is able to be parsed a specially crafted text may cause the application to consume an excessive amount of CPU.
Patches
Upgrade to version 6.0.3, 7.0.2 or later.
Workarounds
Avoid to parse text with a lot of
[
chars.References
For more information
If you have any questions or comments about this advisory:
References