Description
nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions of `{{|`. This issue has been patched in all versions above `0.2.5`. There are currently no known workarounds.
Remediation
References
https://github.com/cainthebest/nitrado.js/blob/v0.2.5/CHANGELOG.md
https://github.com/cainthebest/nitrado.js/security/advisories/GHSA-vqc4-v8hc-h2jg
Related Vulnerabilities
CVE-2018-3721 Vulnerability in maven package org.webjars.npm:lodash.mergewith
CVE-2019-1010266 Vulnerability in maven package org.webjars:lodash
CVE-2020-1950 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2022-24615 Vulnerability in maven package net.lingala.zip4j:zip4j
CVE-2018-20595 Vulnerability in maven package org.hswebframework.web:hsweb-system-oauth2-client-web