CVE-2022-1929
5.9MEDIUMAn exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
Published: 6/2/2022Updated: 11/21/2024
Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
AI AnalysisPowered by AI
Affected Products
devcert_projectdevcert
References
- https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/ExploitThird Party Advisory
- https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/ExploitThird Party Advisory