glob-parent before 6.0.1 and 5.1.2 vulnerable to Regular Expression Denial of Service (ReDoS) #12

Closed
opened 2022-10-26 04:50:12 +00:00 by argoyle · 0 comments
argoyle commented 2022-10-26 04:50:12 +00:00 (Migrated from gitlab.com)

⚠️ dependabot-gitlab has detected security vulnerability for glob-parent in path: /, manifest_file: /package.json but was unable to update it! ⚠️

Package Severity Affected versions Patched versions IDs
glob-parent (NPM) MODERATE < 5.1.2 5.1.2 GHSA-cj88-88mr-972w,CVE-2021-35065

Description

glob-parent before 6.0.1 and 5.1.2 is vulnerable to Regular Expression Denial of Service (ReDoS). This issue is fixed in version 6.0.1 and 5.1.2.

References

⚠️ `dependabot-gitlab` has detected security vulnerability for `glob-parent` in path: `/`, manifest_file: `/package.json` but was unable to update it! ⚠️ * https://github.com/advisories/GHSA-cj88-88mr-972w | Package | Severity | Affected versions | Patched versions | IDs | |-------------------|----------|-------------------|------------------|----------------------------------------| | glob-parent (NPM) | MODERATE | < 5.1.2 | 5.1.2 | `GHSA-cj88-88mr-972w`,`CVE-2021-35065` | # Description glob-parent before 6.0.1 and 5.1.2 is vulnerable to Regular Expression Denial of Service (ReDoS). This issue is fixed in version 6.0.1 and 5.1.2. # References * https://nvd.nist.gov/vuln/detail/CVE-2021-35065 * https://github.com/opensearch-project/OpenSearch-Dashboards/issues/1103 * https://github.com/gulpjs/glob-parent/pull/49 * https://www.mend.io/vulnerability-database/CVE-2021-35065 * https://github.com/gulpjs/glob-parent/pull/36 * https://github.com/gulpjs/glob-parent/releases/tag/v5.1.2 * https://github.com/gulpjs/glob-parent/releases/tag/v6.0.1 * https://github.com/advisories/GHSA-cj88-88mr-972w
argoyle (Migrated from gitlab.com) closed this issue 2022-12-05 13:03:02 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: dancefinder/dancefinder-app#12