GHSA-mvmf-cvfx-qg55

Suggest an improvement
Source
https://github.com/advisories/GHSA-mvmf-cvfx-qg55
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-mvmf-cvfx-qg55/GHSA-mvmf-cvfx-qg55.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mvmf-cvfx-qg55
Aliases
  • CVE-2014-8881
Published
2020-09-01T15:16:43Z
Modified
2023-11-08T03:57:46Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Regular Expression Denial of Service in bleach
Details

All versions of the bleach package are vulnerable to a regular expression denial of service attack when certain types of input are passed into the sanitize function.

Recommendation

The bleach package is not currently maintained, and has not seen an update since 2014.

To mitigate this issue, it is necessary to use an alternative module that is actively maintained and provides similar functionality. There are multiple modules fitting this criteria available on npm..

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-31T18:09:10Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

npm / bleach

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-mvmf-cvfx-qg55/GHSA-mvmf-cvfx-qg55.json"