ZeroHour

CVE-2017-18077

PoC ×2
CVSS 3.0
7.5 high
EPSS
3%p84
Published
()
Modified
Description

index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.

Vendors
brace expansion project
Products
brace expansion
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.