4.3
CVSSv2

CVE-2018-7651

Published: 04/03/2018 Updated: 27/03/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

index.js in the ssri module prior to 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.

Vulnerable Product Search on Vulmon Subscribe to Product

ssri project ssri

Vendor Advisories

Debian Bug report logs - #891980 node-ssri: CVE-2018-7651 Package: src:node-ssri; Maintainer for src:node-ssri is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 3 Mar 2018 15:45:02 UTC Severity: important Tags: fixed-upst ...