CVE-2021-23362 log

Source
Severity Medium
Remote Yes
Type Denial of service
Description
A security issue has been found in Node.js before versions 16.4.1, 14.17.2 and 12.22.2. There is a vulnerability in the hosted-git-info npm module which may be vulnerable to denial of service attacks.
Group Package Affected Fixed Severity Status Ticket
AVG-2129 nodejs-lts-dubnium 10.24.0-2 High Unknown
AVG-2128 nodejs-lts-erbium 12.22.0-2 12.22.3-1 High Fixed
AVG-2127 nodejs-lts-fermium 14.16.0-2 14.17.3-1 High Fixed
AVG-2126 nodejs 16.4.0-1 16.4.1-1 High Fixed
Date Advisory Group Package Severity Type
20 Jul 2021 ASA-202107-33 AVG-2128 nodejs-lts-erbium High multiple issues
20 Jul 2021 ASA-202107-32 AVG-2127 nodejs-lts-fermium High multiple issues
06 Jul 2021 ASA-202107-13 AVG-2126 nodejs High multiple issues
References
https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/#npm-upgrade-hosted-git-info-regular-expression-denial-of-service-redos-medium-cve-2021-23362
https://snyk.io/vuln/SNYK-JS-HOSTEDGITINFO-1088355
https://github.com/npm/hosted-git-info/pull/76
https://github.com/npm/hosted-git-info/commit/bede0dc38e1785e732bf0a48ba6f81a4a908eba3