Terser < 4.8.1 and 5.0.0-5.14.1 - Regular Expression Denial of Service

2022-07-15 00:00
Anonymous

Strategic Overview

Status
Patched in 1.3.0
Affected PluginPublisher Media Kit
Affected Version<= 1.2.1
CVSS5.3Medium
CVECVE-2022-25858
View all Publisher Media Kit vulnerabilities

Vulnerability Overview

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. As this package is used in some WordPress plugins, this could result in the impacted plugins being vulnerable.

Technical Analysis

REMEDIATION: Update to version 1.3.0, or a newer patched version --- IDENTIFIER: CWE-1333 (Inefficient Regular Expression Complexity) The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C