CVE-2024-21539

high

Description

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability.

References

https://security.snyk.io/vuln/SNYK-JS-ESLINTPLUGINKIT-8340627

https://github.com/eslint/rewrite/commit/071be842f0bd58de4863cdf2ab86d60f49912abf

Details

Source: Mitre, NVD

Published: 2024-11-19

Updated: 2024-11-19

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High