Related Vulnerabilities: CVE-2021-23362  

A security issue has been found in Node.js before versions 16.4.1, 14.17.2 and 12.22.2. There is a vulnerability in the hosted-git-info npm module which may be vulnerable to denial of service attacks.

Severity Medium

Remote Yes

Type Denial of service

Description

A security issue has been found in Node.js before versions 16.4.1, 14.17.2 and 12.22.2. There is a vulnerability in the hosted-git-info npm module which may be vulnerable to denial of service attacks.

AVG-2129 nodejs-lts-dubnium 10.24.0-2 High Vulnerable

AVG-2128 nodejs-lts-erbium 12.22.0-2 High Vulnerable

AVG-2127 nodejs-lts-fermium 14.16.0-2 High Vulnerable

AVG-2126 nodejs 16.4.0-1 16.4.1-1 High Fixed

https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/#npm-upgrade-hosted-git-info-regular-expression-denial-of-service-redos-medium-cve-2021-23362
https://snyk.io/vuln/SNYK-JS-HOSTEDGITINFO-1088355
https://github.com/npm/hosted-git-info/pull/76
https://github.com/npm/hosted-git-info/commit/bede0dc38e1785e732bf0a48ba6f81a4a908eba3