GMS-2017-215

ADVISORY - gitlab

Summary

slug is vulnerable to regular expression denial of service is specially crafted untrusted input is passed as input. About k characters can block the event loop for 2 seconds.

Common Weakness Enumeration (CWE)

ADVISORY - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities


GitLab

CREATED

UPDATED

ADVISORY ID

GMS-2017-215

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
slugnpm-->=0.0.0-alphaNot yet available

Severity and metrics

No CVSS data available from this advisory.