terser (JS Package) < 5.14.2 - Denial of Service
2022-07-14 00:00
AnonymousStrategic Overview
StatusPatched in 1.2.0
Affected PluginRetro Winamp Block
Affected Version
<= 1.1.0CVSS3.7Low
CVE
CVE-2022-25858Vulnerability Overview
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.
Technical Analysis
REMEDIATION: Update to version 1.2.0, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C