Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Debug Checkmarx Vulnerability #953

Closed
GadyEilat opened this issue Dec 24, 2023 · 1 comment
Closed

Debug Checkmarx Vulnerability #953

GadyEilat opened this issue Dec 24, 2023 · 1 comment

Comments

@GadyEilat
Copy link

Hey,
After scanning my website recently with Checkmarx, a new vulnerability is shown regarding the debug NPM.
The vulnerability states the following:
"In NPM debug, the enable function accepts a regular expression from user input without escaping it. Arbitrary regular expressions could be injected to cause a Denial of Service attack on the user's browser, otherwise known as a ReDoS (Regular Expression Denial of Service). This is a different issue than CVE-2017-16137."
Is that something you could solve?
Thanks in advance.

@Qix-
Copy link
Member

Qix- commented Dec 24, 2023

Please search the issues before opening new issues.

@Qix- Qix- closed this as completed Dec 24, 2023
@debug-js debug-js locked as spam and limited conversation to collaborators Dec 24, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

No branches or pull requests

2 participants