Open
Description
Package: cross-spawn
Current Version: 7.0.3
Fixed Version: 7.0.5, 6.0.6
Severity: HIGH
Description: Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
References:
- https://access.redhat.com/security/cve/CVE-2024-21538
- https://github.com/moxystudio/node-cross-spawn
- moxystudio/node-cross-spawn@5ff3a07
- moxystudio/node-cross-spawn@640d391
- moxystudio/node-cross-spawn@d35c865
- Backport GHSA-3xgq-45jj-v275 moxystudio/node-cross-spawn#165
- fix: disable regexp backtracking moxystudio/node-cross-spawn#160
- https://nvd.nist.gov/vuln/detail/CVE-2024-21538
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-8366349
- https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230
- https://www.cve.org/CVERecord?id=CVE-2024-21538
This issue was automatically created by the Trivy security scanner.