Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
Remediation
References
https://research.jfrog.com/vulnerabilities/semver-regex-redos-xray-211349/
Related Vulnerabilities
CVE-2022-23302 Vulnerability in maven package log4j:log4j
CVE-2022-31142 Vulnerability in npm package fastify-bearer-auth
CVE-2022-1295 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js
CVE-2021-41862 Vulnerability in maven package com.googlecode.aviator:aviator
CVE-2020-15366 Vulnerability in maven package org.webjars.npm:ajv