Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
⚠️ `dependabot-gitlab` has detected security vulnerability for `semver` in path: `/`, manifest_file: `/package.json` but was unable to update it! ⚠️
* https://github.com/advisories/GHSA-c2qf-rxjj-qqgw
| Package | Severity | Affected versions | Patched versions | IDs |
|--------------|----------|-------------------|------------------|----------------------------------------|
| semver (NPM) | MODERATE | < 5.7.2 | 5.7.2 | `GHSA-c2qf-rxjj-qqgw`,`CVE-2022-25883` |
# Description
Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
# References
* https://nvd.nist.gov/vuln/detail/CVE-2022-25883
* https://github.com/npm/node-semver/pull/564
* https://github.com/npm/node-semver/commit/717534ee353682f3bcf33e60a8af4292626d4441
* https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795
* https://github.com/npm/node-semver/blob/main/classes/range.js#L97-L104
* https://github.com/npm/node-semver/blob/main/internal/re.js#L138
* https://github.com/npm/node-semver/blob/main/internal/re.js#L160
* https://github.com/npm/node-semver/pull/585
* https://github.com/npm/node-semver/commit/928e56d21150da0413a3333a3148b20e741a920c
* https://github.com/npm/node-semver/pull/593
* https://github.com/npm/node-semver/commit/2f8fd41487acf380194579ecb6f8b1bbfe116be0
* https://github.com/advisories/GHSA-c2qf-rxjj-qqgw
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
⚠️
dependabot-gitlabhas detected security vulnerability forsemverin path:/, manifest_file:/package.jsonbut was unable to update it! ⚠️GHSA-c2qf-rxjj-qqgw,CVE-2022-25883Description
Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
References