CVE-2021-23362

Publication date

2021-03-23 16:20:14

Family

snyk

State

PUBLISHED

Description

The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.