7.5
CVE-2023-26115
- EPSS 1.71%
- Veröffentlicht 22.06.2023 05:15:09
- Zuletzt bearbeitet 13.02.2025 17:16:11
- CVE-Watchlists
- Unerledigt
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Word-wrap Project ≫ Word-wrap SwPlatformnode.js Version < 1.2.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.71% | 0.743 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| Snyk | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-1333 Inefficient Regular Expression Complexity
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
https://security.netapp.com/advisory/ntap-20240621-0006/
https://github.com/jonschlinkert/word-wrap/blob/master/index.js%23L39
https://github.com/jonschlinkert/word-wrap/releases/tag/1.2.4
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-4058657
https://security.snyk.io/vuln/SNYK-JS-WORDWRAP-3149973