CVE-2024-21538 - Node.js Cross-Spawn ReDoS Vulnerability

2 weeks ago 9
ARTICLE AD BOX
CVE ID : CVE-2024-21538
Published : Nov. 8, 2024, 5:15 a.m. | 24 minutes ago
Description : Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article