CVE-2023-26115
5.3MEDIUMAll versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
게시됨: 6/22/2023업데이트됨: 2/13/2025
설명
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
AI 분석AI 기반
영향받는 제품
word-wrap_projectword-wrap
참조
- https://github.com/jonschlinkert/word-wrap/blob/master/index.js%23L39Broken Link
- https://github.com/jonschlinkert/word-wrap/releases/tag/1.2.4Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-4058657ExploitThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-WORDWRAP-3149973ExploitThird Party Advisory
- https://github.com/jonschlinkert/word-wrap/blob/master/index.js%23L39Broken Link
- https://github.com/jonschlinkert/word-wrap/releases/tag/1.2.4Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-4058657ExploitThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-WORDWRAP-3149973ExploitThird Party Advisory