Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

serve-favicon vulnerable to RegEx Denial of Service attack #39

Closed
ghost opened this issue Sep 26, 2017 · 1 comment
Closed

serve-favicon vulnerable to RegEx Denial of Service attack #39

ghost opened this issue Sep 26, 2017 · 1 comment
Assignees
Labels

Comments

@ghost
Copy link

ghost commented Sep 26, 2017

This library should upgrade its dependency of fresh to version 0.5.2, because version 0.5.1 has a Regular Expression Denial of Service vulnerability.

$ npm i -g nsp
$ nsp check

(+) 1 vulnerabilities found
┌───────────────┬─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐
│               │ Regular Expression Denial of Service                                                                                                                                    │
├───────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Name          │ fresh                                                                                                                                                                   │
├───────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ CVSS          │ 7.5 (High)                                                                                                                                                              │
├───────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Installed     │ 0.5.1                                                                                                                                                                   │
├───────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Vulnerable    │ < 0.5.2                                                                                                                                                                 │
├───────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Patched       │ >= 0.5.2                                                                                                                                                                │
├───────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Path          │ serve-favicon@2.4.4 > fresh@0.5.1                                                                                                                                       │
├───────────────┼─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ More Info     │ https://nodesecurity.io/advisories/526                                                                                                                                  │
└───────────────┴─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘
@dougwilson dougwilson self-assigned this Sep 26, 2017
@dougwilson
Copy link
Contributor

Version 2.4.5 will be published as soon as the CI jobs complete.

nevilm-lt pushed a commit to nevilm-lt/serve-favicon that referenced this issue Mar 14, 2022
nevilm-lt pushed a commit to nevilm-lt/serve-favicon that referenced this issue Apr 21, 2022
nevilm-lt pushed a commit to nevilm-lt/serve-favicon that referenced this issue Apr 22, 2022
nevilm-lt pushed a commit to nevilm-lt/serve-favicon that referenced this issue Apr 22, 2022
nevilm-lt pushed a commit to nevilm-lt/serve-favicon that referenced this issue Apr 22, 2022
himanshiLt pushed a commit to himanshiLt/serve-favicon that referenced this issue Jun 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant