Description
The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of service when specifically crafted untrusted user input is passed into the underscore or unescapeHTML methods.
Remediation
References
https://github.com/jprichardson/string.js/issues/212
https://nodesecurity.io/advisories/536
Related Vulnerabilities
CVE-2011-0013 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2020-7631 Vulnerability in npm package diskusage-ng
CVE-2021-23632 Vulnerability in npm package git
CVE-2022-23059 Vulnerability in maven package com.shopizer:shopizer
CVE-2020-28458 Vulnerability in maven package org.webjars.npm:datatables.net