説明
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
AI分析AIによる分析
影響を受ける製品
devcert_projectdevcert
参照
- https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/ExploitThird Party Advisory
- https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/ExploitThird Party Advisory