Skip to content

high vulnerability issue in dependent package minimatch #252

Open
@ahernandez111

Description

@ahernandez111

Description: minimatch package versions before 3.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS). It's possible to cause a denial of service when calling function braceExpand (The regex /{.*}/ is vulnerable and can be exploited).

Solution: Update minimatch version 3.0.4 to 3.0.5.

Vulnerability Link : isaacs/minimatch@a8763f4

Reference: grafana/grafana-image-renderer#329

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions