electron/get

Regular Expression Denial of Service (ReDoS) Security Vulnerability

justingatlin-clear opened this issue · 1 comments

A ReDoS vulnerability has been discovered in package http-cache-semantics currently being used by get.

Versions of http-cache-semantics < 4.1.1 are affected.

More information can be found here

Upgrading got to at least version 12.5.0 will resolve this vulnerability.

Duplicate of #242

This repo specifies http-cache-semantics@4.1.1 in the lockfile:

https://github.com/electron/get/blob/21d1494d656dad752d5ac90d6ce0f3be8155575d/yarn.lock#L2857-L2860C1