Debug Checkmarx Vulnerability
GadyEilat opened this issue · 1 comments
GadyEilat commented
Hey,
After scanning my website recently with Checkmarx, a new vulnerability is shown regarding the debug NPM.
The vulnerability states the following:
"In NPM debug, the enable function accepts a regular expression from user input without escaping it. Arbitrary regular expressions could be injected to cause a Denial of Service attack on the user's browser, otherwise known as a ReDoS (Regular Expression Denial of Service). This is a different issue than CVE-2017-16137."
Is that something you could solve?
Thanks in advance.
Qix- commented
Please search the issues before opening new issues.