Vulnerability Details CVE-2021-43309
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when an attacker is able to supply arbitrary input to the "URI.expand" method
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.8%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2021-43309
-
cpe:2.3:a:litejs:uri-template-lite:-
-
cpe:2.3:a:litejs:uri-template-lite:0.0.1
-
cpe:2.3:a:litejs:uri-template-lite:0.0.2
-
cpe:2.3:a:litejs:uri-template-lite:0.0.3
-
cpe:2.3:a:litejs:uri-template-lite:0.0.4
-
cpe:2.3:a:litejs:uri-template-lite:0.0.5
-
cpe:2.3:a:litejs:uri-template-lite:0.1.0
-
cpe:2.3:a:litejs:uri-template-lite:0.1.1
-
cpe:2.3:a:litejs:uri-template-lite:0.1.10
-
cpe:2.3:a:litejs:uri-template-lite:0.1.11
-
cpe:2.3:a:litejs:uri-template-lite:0.1.2
-
cpe:2.3:a:litejs:uri-template-lite:0.1.3
-
cpe:2.3:a:litejs:uri-template-lite:0.1.4
-
cpe:2.3:a:litejs:uri-template-lite:0.1.6
-
cpe:2.3:a:litejs:uri-template-lite:0.1.7
-
cpe:2.3:a:litejs:uri-template-lite:0.1.8
-
cpe:2.3:a:litejs:uri-template-lite:19.11.0
-
cpe:2.3:a:litejs:uri-template-lite:19.12.0
-
cpe:2.3:a:litejs:uri-template-lite:19.4.0
-
cpe:2.3:a:litejs:uri-template-lite:20.5.0
-
cpe:2.3:a:litejs:uri-template-lite:22.1.0