Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Regular Expression Denial of Service (ReDoS)
Vulnerability Description
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
N/A
Vulnerability Title
terser 安全漏洞
Vulnerability Description
terser是terser个人开发者的一个用于 ES6+ 的 JavaScript 解析器、处理程序和压缩器工具包。 terser 4.8.1 之前版本、5.0.0 和 5.14.2 之前版本存在安全漏洞,该漏洞源于正则表达式的使用不安全,导致容易受到正则表达式拒绝服务 (ReDoS) 的攻击。
CVSS Information
N/A
Vulnerability Type
N/A