Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
Remediation
References
https://research.jfrog.com/vulnerabilities/semver-regex-redos-xray-211349/
Related Vulnerabilities
CVE-2019-1010091 Vulnerability in maven package org.webjars:tinymce
CVE-2021-23472 Vulnerability in npm package bootstrap-table
CVE-2021-23364 Vulnerability in npm package browserslist
CVE-2021-21384 Vulnerability in npm package shescape
CVE-2018-6561 Vulnerability in maven package org.webjars.bowergithub.dojo:dijit