ansi-regex >=2.1.1 <3.0.1 >=4.0.0 <4.1.1 >=5.0.0 <5.0.1 >=6.0.0 <6.0.1 - Regular Expression Denial of Service (ReDoS)

2021-09-09 00:00
Anonymous

Strategic Overview

Status
Patched in 1.0.5
Affected Version<= 1.0.4
CVSS7.5High
CVEN/A
View all Insert Special Characters vulnerabilities

Vulnerability Overview

ansi-regex is vulnerable to Inefficient Regular Expression Complexity. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.

Technical Analysis

REMEDIATION: Update to version 1.0.5, or a newer patched version --- IDENTIFIER: CWE-1333 (Inefficient Regular Expression Complexity) The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C