漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Denial of service in fast-csv
Vulnerability Description
Fast-csv is an npm package for parsing and formatting CSVs or any other delimited value file in node. In fast-cvs before version 4.3.6 there is a possible ReDoS vulnerability (Regular Expression Denial of Service) when using ignoreEmpty option when parsing. This has been patched in `v4.3.6` You will only be affected by this if you use the `ignoreEmpty` parsing option. If you do use this option it is recommended that you upgrade to the latest version `v4.3.6` This vulnerability was found using a CodeQL query which identified `EMPTY_ROW_REGEXP` regular expression as vulnerable.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
C2FO Fast-csv 资源管理错误漏洞
Vulnerability Description
C2FO Fast-csv是美国Packwood(C2FO)公司的一个基于Typescript的用于解析和格式化CSV格式文件的代码库。 Fast-csv 存在安全漏洞,该漏洞源于解析时使用ignoreEmpty选项可能存在重dos漏洞(正则表达式拒绝服务)。
CVSS Information
N/A
Vulnerability Type
N/A