ansi-regex >=2.1.1 <3.0.1 >=4.0.0 <4.1.1 >=5.0.0 <5.0.1 >=6.0.0 <6.0.1 - Regular Expression Denial of Service (ReDoS)
2021-09-09 00:00
AnonymousStrategic Overview
StatusPatched in 1.0.5
Affected PluginInsert Special Characters
Affected Version
<= 1.0.4CVSS7.5High
CVE
N/AVulnerability Overview
ansi-regex is vulnerable to Inefficient Regular Expression Complexity. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.
Technical Analysis
REMEDIATION: Update to version 1.0.5, or a newer patched version --- IDENTIFIER: CWE-1333 (Inefficient Regular Expression Complexity) The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C