A vulnerability was found in Braces versions prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.
The product specifies a regular expression in a way that causes data to be improperly matched or compared.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1547272 | issue tracking third party advisory patch |
https://snyk.io/vuln/npm:braces:20180219 | third party advisory exploit |