mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-01 19:20:58 +00:00
23 lines
1.0 KiB
Markdown
23 lines
1.0 KiB
Markdown
### [CVE-2023-26115](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26115)
|
|

|
|

|
|

|
|
&color=brighgreen)
|
|
|
|
### Description
|
|
|
|
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
|
|
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-4058657
|
|
- https://security.snyk.io/vuln/SNYK-JS-WORDWRAP-3149973
|
|
|
|
#### Github
|
|
- https://github.com/git-kick/ioBroker.e3dc-rscp
|
|
- https://github.com/martinjackson/simple-widgets
|
|
- https://github.com/seal-community/patches
|
|
- https://github.com/sebhildebrandt/word-wrap-next
|
|
|