Uploaded image for project: 'mod-graphql'
  1. mod-graphql
  2. MODGQL-143

Update validator from ^10.0.0 to ^13.7.0 fixing ReDoS (CVE-2021-3765)

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • TBD
    • Resolution: Done
    • 1.9.0
    • 1.10.0
    • Thor

    Description

      validator < 13.7.0 is vulnerable to a ReDoS attack (Regular Expression Denial of Service caused by Inefficient Regular Expression Complexity): https://nvd.nist.gov/vuln/detail/CVE-2021-3765

      mod-graphql requires z-schema@3.21.0 requires validator@^10.0.0.

      TestRail: Results

        Attachments

          Activity

            People

              mike Mike Taylor
              julianladisch Julian Ladisch
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                TestRail: Runs

                  TestRail: Cases