Regular Expression Denial of Service (ReDoS) Vulnerability in ssri Module for Node.js

Regular Expression Denial of Service (ReDoS) Vulnerability in ssri Module for Node.js

CVE-2018-7651 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:N/A:P

index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.

Learn more about our Web Application Penetration Testing UK.