Regular Expression Denial of Service vulnerability in the ansi-regex package in versions < 6.0.1
See original GitHub issuesequelize-cli@6.2.0
| ±- cli-color@1.4.0
| | -- ansi-regex@2.1.1 |
– yargs@13.3.2
| ±- cliui@5.0.0
| | -- strip-ansi@5.2.0 | |
– ansi-regex@4.1.0
| -- string-width@3.1.0 |
– strip-ansi@5.2.0
| `-- ansi-regex@4.1.0
Can Sequelize-cli team check on this There’s a Regular Expression Denial of Service vulnerability in the ansi-regex package in versions < 6.0.1: https://app.snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
Can you please update the cli-color and yargs they have fixed the issue
Issue Analytics
- State:
- Created 2 years ago
- Reactions:3
- Comments:8 (3 by maintainers)
Top Results From Across the Web
There's a Regular Expression Denial of Service vulnerability ...
There's a Regular Expression Denial of Service vulnerability in the ansi-regex package in versions < 6.0.1: #41.
Read more >Regular Expression Denial of Service (ReDoS) in ansi-regex
Overview. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to the sub-patterns [[\ ...
Read more >Regular Expression Denial Of Service (ReDoS) Vulnerability ...
ansi -regex is vulnerable to regular expression denial of service. The vulnerability exists due to an inefficient handling of user-provided string pattern, ...
Read more >CVE-2021-3807 nodejs-ansi-regex - Red Hat Bugzilla
A regular expression denial of service (ReDoS) vulnerability was found in nodejs-ansi-regex. This could possibly cause an application using ansi-regex to use ......
Read more >ansi-regex >=2.1.1 <3.0.1 >=4.0.0 <4.1.1 >=5.0.0 ... - Wordfence
ansi -regex is vulnerable to Inefficient Regular Expression Complexity. Some WordPress plugins and themes use this dependency though that doesn't ...
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
fixed in 6.3.0
Thanks @sdepold @fncolon for fixing the vulnerability .