Skip to content

[Security] ReDoS vulnerability #7927

Closed as not planned
Closed as not planned
@folortin

Description

@folortin

Waiting for

Vulnerability Information

Package: npm/cross-spawn
Vulnerabilities
cross-spawn: >= 7.0.0, < 7.0.5, fixed in 7.0.5
cross-spawn: < 6.0.6, fixed in 6.0.6

Manifest Path: package-lock.json
Scope: runtime

Advisory:

ID: https://github.com/advisories/GHSA-3xgq-45jj-v275
CVE ID: https://github.com/advisories/GHSA-3xgq-45jj-v275
Severity: high
Alert url: 

https://github.com/Wise-Ingegneria/W-Radio-TS/security/dependabot/11
Summary: Regular Expression Denial of Service (ReDoS) in cross-spawn

Description:
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

References:

https://nvd.nist.gov/vuln/detail/CVE-2024-21538

moxystudio/node-cross-spawn#160
moxystudio/node-cross-spawn@5ff3a07
moxystudio/node-cross-spawn@640d391
https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230

https://github.com/moxystudio/node-cross-spawn/issues/165
https://github.com/moxystudio/node-cross-spawn/commit/d35c865b877d2f9ded7c1ed87521c2fdb689c8dd
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-8366349
https://github.com/advisories/GHSA-3xgq-45jj-v275

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions