Vulnerabilities
Vulnerable Software
Adaltas:  >> Printf  >> 0.2.1  Security Vulnerabilities
The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string /\%(?:\(([\w_.]+)\)|([1-9]\d*)\$)?([0 +\-\]*)(\*|\d+)?(\.)?(\*|\d+)?[hlL]?([\%bscdeEfFgGioOuxX])/g in lib/printf.js. The vulnerable regular expression has cubic worst-case time complexity.
CVSS Score
5.3
EPSS Score
0.004
Published
2021-03-12


Contact Us

Shodan ® - All rights reserved