icon

We found results for “

WS-2018-0069

Good to know:

icon
icon

Date: February 14, 2018

Version of is-my-json-valid before 1.4.1 or 2.17.2 are vulnerable to regular expression denial of service (ReDoS) via the email validation function.

Language: Java

Severity Score

Severity Score

Weakness Type (CWE)

Incorrect Regular Expression

CWE-185

Top Fix

icon

Upgrade Version

Upgrade to version Tools.Npm - no_fix;nodejs - 8.8.1;erdiko/user-admin - no_fix;erdiko/user-admin - dev-ER-91;spiral/toolkit - v0.8.20;spiral/toolkit - v0.8.18;spiral/toolkit - v0.9.0;chrisbraybrooke/laravel-ecommerce - dev-form-field-key;chrisbraybrooke/laravel-ecommerce - 0.0.56;chrisbraybrooke/laravel-ecommerce - 0.0.11;MIDIator.WebClient - 1.0.105;Yarn.MSBuild - 0.22.0;Npm - no_fix;node-sass-bundle - no_fix;node-sass-bundle - 1.0.2;oburatongoi/productivity - 0.3.36;oburatongoi/productivity - 0.0.13;mpcmf/mpcmf-web-app - no_fix;mpcmf/mpcmf-web-app - 1.0.0.x-dev;Yarnpkg.Yarn - 0.26.1;Ncapsulate.Node.Shadow - no_fix;Npm3 - no_fix;computerundsound/curserver - no_fix;computerundsound/curserver - 2.2.0;limefamily/yii2-limetheme - 1.0.12;yuan1994/wechat_web_devtools - 0.15.152901-core;Npm.js - no_fix;NodeBin - no_fix;jquery - 3.4.0;jsdom - 11.11.0;is-my-json-valid - 2.17.2;dreamfactory/df-api-docs-ui - 1.1.0;humanmade/coding-standards - dev-dependabot/npm_and_yarn/json-schema-0.4.0;Betclic.BuildTools.Node - no_fix;nanny-sys - no_fix;ilhanet/erpnet-widget-resource - no_fix;kayrules/solatjakim-api-site - dev-version-1.0;azure-cli - no_fix;svg2png - no_fix;neon-sys - 0.1.11;z3/t3build-node - 1.0.11;Raml.Parser - 1.0.7;zombie.js - no_fix;org.webjars.npm:bower:1.8.12;org.webjars.npm:bourbon-neat:2.1.0;org.webjars:browser-sync:no_fix;org.webjars.npm:is-my-json-valid:2.17.2;org.webjars:npm:4.0.2;org.webjars:npm:4.4.4

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us