Vulnerability Details CVE-2018-7651
index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.4%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2018-7651
-
cpe:2.3:a:ssri_project:ssri:1.0.0
-
cpe:2.3:a:ssri_project:ssri:2.0.0
-
cpe:2.3:a:ssri_project:ssri:3.0.0
-
cpe:2.3:a:ssri_project:ssri:3.0.1
-
cpe:2.3:a:ssri_project:ssri:3.0.2
-
cpe:2.3:a:ssri_project:ssri:4.0.0
-
cpe:2.3:a:ssri_project:ssri:4.1.0
-
cpe:2.3:a:ssri_project:ssri:4.1.1
-
cpe:2.3:a:ssri_project:ssri:4.1.2
-
cpe:2.3:a:ssri_project:ssri:4.1.3
-
cpe:2.3:a:ssri_project:ssri:4.1.4
-
cpe:2.3:a:ssri_project:ssri:4.1.5
-
cpe:2.3:a:ssri_project:ssri:4.1.6
-
cpe:2.3:a:ssri_project:ssri:5.0.0
-
cpe:2.3:a:ssri_project:ssri:5.1.0
-
cpe:2.3:a:ssri_project:ssri:5.2.0
-
cpe:2.3:a:ssri_project:ssri:5.2.1