A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for Node.js.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://github.com/progfay/scrapbox-parser/pull/519 | third party advisory patch |
https://github.com/progfay/scrapbox-parser/pull/539 | third party advisory patch |
https://github.com/progfay/scrapbox-parser/pull/540 | third party advisory patch |
https://security.netapp.com/advisory/ntap-20210326-0002/ | third party advisory |