Description
The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the event loop causing a denial of service condition.
Remediation
References
https://github.com/blakeembrey/no-case/issues/17
https://nodesecurity.io/advisories/529
Related Vulnerabilities
CVE-2019-19919 Vulnerability in maven package org.webjars.npm:handlebars
CVE-2020-10758 Vulnerability in maven package org.keycloak:keycloak-wildfly-server-subsystem
CVE-2020-7733 Vulnerability in npm package ua-parser-js
CVE-2022-43427 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2019-13990 Vulnerability in maven package org.quartz-scheduler.internal:quartz-core