5.3

CVE-2021-23388

Regular Expression Denial of Service (ReDoS)

The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via email validation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Forms ProjectForms SwPlatformnode.js Version < 1.2.1
Forms ProjectForms SwPlatformnode.js Version >= 1.3.0 < 1.3.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.65% 0.734
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
report@snyk.io 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/caolan/forms/pull/214
Third Party Advisory
https://github.com/caolan/forms/pull/214/commits/d4bd5b5febfe49c1f585f162e04ec810f8dc47a0
Patch
Third Party Advisory
https://snyk.io/vuln/SNYK-JS-FORMS-1296389
Patch
Third Party Advisory