Description
Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(path, pattern)` in Minimatch 3.0.1 and earlier is vulnerable to ReDoS in the `pattern` parameter.
Remediation
References
https://nodesecurity.io/advisories/118
Related Vulnerabilities
CVE-2020-8298 Vulnerability in npm package fs-path
CVE-2021-34078 Vulnerability in npm package lifion-verify-deps
CVE-2020-8570 Vulnerability in maven package io.kubernetes:client-java
CVE-2022-32114 Vulnerability in npm package @strapi/strapi
CVE-2021-23358 Vulnerability in maven package org.webjars.bowergithub.jashkenas:underscore