minimatch ReDoS vulnerability #167
Labels
Auto Create Issues
Label for Auto Created Issues
High
This label for Security Severity only
Security
Label for Security Issues
Milestone
Description
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
Severity Check
Severity Number
7.5
CVSS base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-400
CVE ID
CVE-2022-3517
GHSA ID
GHSA-f8q6-p94x-37v3
Information
Package
minimatch (npm)
Affected versions
< 3.0.5
Patched versions
3.0.5
References
https://nvd.nist.gov/vuln/detail/CVE-2022-3517
PRISMA-2022-0039 - High vulnerability grafana/grafana-image-renderer#329
isaacs/minimatch@a8763f4
Upgrade to npm 8.5.3 in 16.x to alleviate PRISMA-2022-0039 nodejs/node#42510
The text was updated successfully, but these errors were encountered: