cleantalk
Vulnerabilities and Security Researches

Publisher Media Kit, CVE-2022-25858

CVE, Research URL

CVE-2022-25858

Application

Publisher Media Kit

Published on
Jul 16, 2022
Research Description
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
Affected versions
Min -, max 1.3.0.
Status
vulnerable