Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
Remediation
References
https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/
Related Vulnerabilities
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:element-connector
CVE-2023-45133 Vulnerability in maven package org.webjars.npm:babel__traverse
CVE-2017-16215 Vulnerability in npm package sgqserve
CVE-2022-21164 Vulnerability in npm package node-lmdb
CVE-2023-43123 Vulnerability in maven package org.apache.storm:storm-server