glob-parent before 6.0.1 vulnerable to Regular Expression Denial of Service (ReDoS) #11

Closed
opened 2022-10-26 04:42:47 +00:00 by argoyle · 0 comments
argoyle commented 2022-10-26 04:42:47 +00:00 (Migrated from gitlab.com)

⚠️ dependabot-gitlab has detected security vulnerability for glob-parent in path: /, manifest_file: /package.json but was unable to update it! ⚠️

Package Severity Affected versions Patched versions IDs
glob-parent (NPM) MODERATE < 6.0.1 6.0.1 GHSA-cj88-88mr-972w,CVE-2021-35065

Description

glob-parent before 6.0.1 is vulnerable to Regular Expression Denial of Service (ReDoS).

References

⚠️ `dependabot-gitlab` has detected security vulnerability for `glob-parent` in path: `/`, manifest_file: `/package.json` but was unable to update it! ⚠️ * https://github.com/advisories/GHSA-cj88-88mr-972w | Package | Severity | Affected versions | Patched versions | IDs | |-------------------|----------|-------------------|------------------|----------------------------------------| | glob-parent (NPM) | MODERATE | < 6.0.1 | 6.0.1 | `GHSA-cj88-88mr-972w`,`CVE-2021-35065` | # Description glob-parent before 6.0.1 is vulnerable to Regular Expression Denial of Service (ReDoS). # References * https://nvd.nist.gov/vuln/detail/CVE-2021-35065 * https://github.com/opensearch-project/OpenSearch-Dashboards/issues/1103 * https://github.com/gulpjs/glob-parent/pull/49 * https://www.mend.io/vulnerability-database/CVE-2021-35065 * https://github.com/advisories/GHSA-cj88-88mr-972w
argoyle (Migrated from gitlab.com) closed this issue 2022-12-05 13:02:58 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: dancefinder/dancefinder-app#11