GHSA-vqc4-v8hc-h2jg
Dashboard / Vulnerabilities / GHSA-vqc4-v8hc-h2jg
Summary: Polynomial regular expression used on uncontrolled data in nitrado.js
Details: ### Impact Possible ReDoS with lib input of `{{` and with many repetitions of `{{|` ### Patches Patched in all versions above `0.2.5` ### Workarounds No known work arounds. ### References - OWASP: [Regular expression Denial of Service - ReDoS](https://www.owasp.org/index.php/Regular_expression_Denial_of_Service_-_ReDoS) - Wikipedia: [ReDoS](https://en.wikipedia.org/wiki/ReDoS). - Wikipedia: [Time complexity](https://en.wikipedia.org/wiki/Time_complexity). - James Kirrage, Asiri Rathnayake, Hayo Thielecke: [Static Analysis for Regular Expression Denial-of-Service Attack](http://www.cs.bham.ac.uk/~hxt/research/reg-exp-sec.pdf). - Common Weakness Enumeration: [CWE-1333](https://cwe.mitre.org/data/definitions/1333.html). - Common Weakness Enumeration: [CWE-400](https://cwe.mitre.org/data/definitions/400.html).
References: https://github.com/cainthebest/nitrado.js/security/advisories/GHSA-vqc4-v8hc-h2jg, https://nvd.nist.gov/vuln/detail/CVE-2022-36034, https://github.com/cainthebest/nitrado.js, https://github.com/cainthebest/nitrado.js/blob/v0.2.5/CHANGELOG.md
Affected packages
Package
Name: nitrado.js
Purl: pkg:npm/nitrado.js
Affected ranges
Type: SEMVER
Events:
