OSV 1.4.0 · github-reviewed · 修改于 2020-09-01 02:34
发布时间
2019-06-15 00:26
GitHub 审查时间
2019-06-15 00:24
NVD 发布时间
—
源文件
advisories/github-reviewed/2019/06/GHSA-v2p6-4mp7-3r9v/GHSA-v2p6-4mp7-3r9v.json
Versions of underscore.string prior to 3.3.5 are vulnerable to Regular Expression Denial of Service (ReDoS).
The function unescapeHTML is vulnerable to ReDoS due to an overly-broad regex. The slowdown is approximately 2s for 50,000 characters but grows exponentially with larger inputs.
Upgrade to version 3.3.5 or higher.