Skip to content

トピトピニュース

Header Image
Archive

Month: July 2018

3 Posts

Featured

Posted byGitHub
[defaults-deep] Prototype Pollution in defaults-deep
Posted byGitHub
[slug] Regular Expression Denial of Service in slug
Posted byGitHub
[eslint-config-eslint] Malicious Package in eslint-scope

[defaults-deep] Prototype Pollution in defaults-deep

  • Posted inLOW
  • Posted byGitHub
  • 07/27/201809/26/2022

Versions of default-deep before 0.2.4 are vulnerable to prototype pollution
Recommendation
Update to version 0.2.4 or later.
References

https://nvd.nist.gov/vuln/detail/CVE-2018-3723
https://hackerone.com/reports/310514
https://github.com/advisories/G…

[slug] Regular Expression Denial of Service in slug

  • Posted inMODERATE
  • Posted byGitHub
  • 07/25/201809/20/2022

Affected versions of slug are vulnerable to a regular expression denial of service when parsing untrusted user input.
The issue is low severity, as it takes 50,000 characters to cause the event loop to block for 2 seconds,
About 50k characters can bloc…

[eslint-config-eslint] Malicious Package in eslint-scope

  • Posted inCRITICAL
  • Posted byGitHub
  • 07/13/201809/08/2022

Version 3.7.2 of eslint-scope was published without authorization and was found to contain malicious code. This code would read the users .npmrc file and send any found authentication tokens to 2 remote servers.
Recommendation
The best course of action…

トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close