Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency Vulnerability (VDB-217448) #255

Open
KaiSchwarz-cnic opened this issue Feb 7, 2023 · 1 comment
Open

Dependency Vulnerability (VDB-217448) #255

KaiSchwarz-cnic opened this issue Feb 7, 2023 · 1 comment

Comments

@KaiSchwarz-cnic
Copy link

A vulnerability was found in Woorank robots-txt-guard. It has been rated as problematic. Affected by this issue is the function makePathPattern of the file lib/patterns.js. The manipulation of the argument pattern leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. The name of the patch is c03827cd2f9933619c23894ce7c98401ea824020. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217448.

Severity: High 7.5 / 10

robots-txt-guard -> affected versions: < 1.0.2, patched in: 1.0.2

Cheers!

@leviwheatcroft
Copy link

Sorry I don't mean to make a "me too" type comment but given the "needs confirmation" tag, I've also run into this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants