Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
Remediation
References
https://research.jfrog.com/vulnerabilities/semver-regex-redos-xray-211349/
Related Vulnerabilities
CVE-2022-31166 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2020-7710 Vulnerability in npm package safe-eval
CVE-2020-11007 Vulnerability in maven package com.shopizer:sm-core-model
CVE-2020-36518 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-4565 Vulnerability in maven package cn.hutool:hutool-core