Description
A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: Low
Affected Packages3 packages
🔴Vulnerability Details
3GHSARegular Expression Denial of Service (ReDoS) in braces↗2022-01-06 ▶ OSVRegular Expression Denial of Service (ReDoS) in braces↗2022-01-06 ▶ OSVCVE-2018-1109: A vulnerability was found in Braces versions prior to 2↗2021-03-30 ▶ 📋Vendor Advisories
2Red Hatnodejs-braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js↗2018-02-19 ▶ DebianCVE-2018-1109: node-braces - A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Af...↗2018 ▶ 💬Community
2BugzillaCVE-2018-1109 nodejs-braces: braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js [fedora-28]↗2018-06-29 ▶ BugzillaCVE-2018-1109 nodejs-braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js↗2018-02-20 ▶