View all vulnerabilities

CVE-2021-23362

Regular Expression Denial of Service in hosted-git-info

The npm package `hosted-git-info` before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Vulnerability Details
Score
5.3
Score Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Versions
hosted-git-info < 2.8.9; hosted-git-info >= 3.0.0 < 3.0.8
Severity
Medium
Ecosystem
JavaScript
Publish Date
May 6, 2021
Modified Date
January 14, 2025