cve/2021/CVE-2021-23354.md
2024-05-25 21:48:12 +02:00

866 B

CVE-2021-23354

Description

The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string /%(?:(([\w_.]+))|([1-9]\d*)$)?([0 +-]*)(*|\d+)?(.)?(*|\d+)?[hlL]?([%bscdeEfFgGioOuxX])/g in lib/printf.js. The vulnerable regular expression has cubic worst-case time complexity.

POC

Reference

No PoCs from references.

Github