Description
The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop for around 10 seconds.
Remediation
References
https://github.com/indexzero/TimeSpan.js/issues/10
https://nodesecurity.io/advisories/533
Related Vulnerabilities
CVE-2019-10317 Vulnerability in maven package org.jvnet.hudson.plugins:sitemonitor
CVE-2022-34113 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2022-1233 Vulnerability in maven package org.webjars.npm:urijs
CVE-2020-28277 Vulnerability in maven package org.webjars.npm:dset
CVE-2020-10727 Vulnerability in maven package org.apache.activemq:artemis-core-client