GHSA-v2p6-4mp7-3r9v

Suggest an improvement
Source
https://github.com/advisories/GHSA-v2p6-4mp7-3r9v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-v2p6-4mp7-3r9v/GHSA-v2p6-4mp7-3r9v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v2p6-4mp7-3r9v
Downstream
Published
2019-06-14T16:26:22Z
Modified
2020-08-31T18:34:16Z
Summary
Regular Expression Denial of Service in underscore.string
Details

Versions of underscore.string prior to 3.3.5 are vulnerable to Regular Expression Denial of Service (ReDoS).

The function unescapeHTML is vulnerable to ReDoS due to an overly-broad regex. The slowdown is approximately 2s for 50,000 characters but grows exponentially with larger inputs.

Recommendation

Upgrade to version 3.3.5 or higher.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2019-06-14T16:24:01Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

npm / underscore.string

Package

Name
underscore.string
View open source insights on deps.dev
Purl
pkg:npm/underscore.string

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.3.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-v2p6-4mp7-3r9v/GHSA-v2p6-4mp7-3r9v.json"