CVE-2018-1109Incorrect Regular Expression in Project Braces

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 42.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateJan 6

Description

A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

npmbraces_project/braces2.2.02.3.1

Patches

🔴Vulnerability Details

3
GHSA
Regular Expression Denial of Service (ReDoS) in braces2022-01-06
OSV
Regular Expression Denial of Service (ReDoS) in braces2022-01-06
OSV
CVE-2018-1109: A vulnerability was found in Braces versions prior to 22021-03-30

📋Vendor Advisories

2
Red Hat
nodejs-braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js2018-02-19
Debian
CVE-2018-1109: node-braces - A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Af...2018

💬Community

2
Bugzilla
CVE-2018-1109 nodejs-braces: braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js [fedora-28]2018-06-29
Bugzilla
CVE-2018-1109 nodejs-braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js2018-02-20