This repository has been archived by the owner on Jan 18, 2024. It is now read-only.
CVE-2022-25858 (High) detected in terser-4.7.0.tgz #62
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-25858 - High Severity Vulnerability
JavaScript parser, mangler/compressor and beautifier toolkit for ES6+
Library home page: https://registry.npmjs.org/terser/-/terser-4.7.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/terser/package.json
Dependency Hierarchy:
Found in base branch: master
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
Publish Date: 2022-07-15
URL: CVE-2022-25858
Base Score Metrics:
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25858
Release Date: 2022-07-15
Fix Resolution (terser): 5.15.0
Direct dependency fix Resolution (@angular-devkit/build-angular): 12.2.18
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: