Headline
CVE-2017-20165: fix: remove ReDoS regexp by zhuangya · Pull Request #504 · debug-js/debug
A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to version 3.1.0 is able to address this issue. The name of the patch is c38a0166c266a679c8de012d4eaccec3f944e685. It is recommended to upgrade the affected component. The identifier VDB-217665 was assigned to this vulnerability.
Conversation
2 similar comments
TooTallNate pushed a commit that referenced this pull request
Sep 22, 2017
platinumazure added a commit to eslint/eslint that referenced this pull request
Dec 18, 2017
This version of debug addresses a minor ReDoS issue. See debug-js/debug#501, debug-js/debug#504 for more information. Looking at the rest of the changelog, this should be a pretty low-risk upgrade.
aladdin-add pushed a commit to eslint/eslint that referenced this pull request
Dec 19, 2017
This version of debug addresses a minor ReDoS issue. See debug-js/debug#501, debug-js/debug#504 for more information. Looking at the rest of the changelog, this should be a pretty low-risk upgrade.
sodawy added a commit to sodawy/session that referenced this pull request
Jan 6, 2018
stenalpjolly added a commit to stenalpjolly/express that referenced this pull request
Aug 30, 2018
This was referenced
Dec 17, 2018
This was referenced
Jan 15, 2019
This was referenced
Jan 31, 2019
This was referenced
Feb 1, 2019
This was referenced
Apr 30, 2019
debug-js locked as off-topic and limited conversation to collaborators
Jun 25, 2019
Related news
A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to version 3.1.0 is able to address this issue. The name of the patch is c38a0166c266a679c8de012d4eaccec3f944e685. It is recommended to upgrade the affected component. The identifier VDB-217665 was assigned to this vulnerability.