Description
All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.
Remediation
References
https://github.com/stevemao/trim-off-newlines/blob/master/index.js%23L6
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1567197
https://snyk.io/vuln/SNYK-JS-TRIMOFFNEWLINES-1296850
Related Vulnerabilities
CVE-2022-36083 Vulnerability in maven package org.webjars.npm:jose
CVE-2016-10518 Vulnerability in maven package org.webjars.npm:ws
CVE-2022-41915 Vulnerability in maven package io.netty:netty-codec
CVE-2022-45389 Vulnerability in maven package com.cloudbees.jenkins.plugins:xpdev
CVE-2020-28500 Vulnerability in maven package org.fujion.webjars:lodash