CVE-2022-1929
Regular expression denial of service in devcert
7.5
HIGH
CVSS 3.1
EPSS 0.18%
Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
How to fix CVE-2022-1929
To remediate CVE-2022-1929, upgrade the affected package to a fixed version below.
- npm/devcert—upgrade to 1.2.1 or later
Is CVE-2022-1929 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.2.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |