Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method
Remediation
References
https://research.jfrog.com/vulnerabilities/devcert-redos-xray-211352/
Related Vulnerabilities
CVE-2020-7614 Vulnerability in npm package npm-programmatic
CVE-2021-23384 Vulnerability in npm package koa-remove-trailing-slashes
CVE-2022-23464 Vulnerability in maven package com.nepxion:discovery-plugin-admin-center
CVE-2022-45206 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core