CVE-2022-1929
5.9MEDIUMAn exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
게시됨: 6/2/2022업데이트됨: 11/21/2024
설명
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
AI 분석AI 기반
영향받는 제품
devcert_projectdevcert
참조
- https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/ExploitThird Party Advisory
- https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/ExploitThird Party Advisory