You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
vulnerability issue reported in our scan "Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range"
Could you please bump the semver version to latest or highest than 7.5.2.
The text was updated successfully, but these errors were encountered:
Like most CVEs, it's a false positive. We're not using new Range nor are we doing anything that wouldn't be a self-attack (ie, not an attack).
We can't ever bump the semver version because v7 drops support for engines we support, so unless the fix is backported to v6, it'll just have to remain a false positive. However, the semver team has indeed backported it to v6, so you don't have to do anything but update.
vulnerability issue reported in our scan "Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range"
Could you please bump the
semver
version to latest or highest than 7.5.2.The text was updated successfully, but these errors were encountered: