Candidate: CVE-2016-10540 PublicDate: 2018-05-31 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10540 https://nodesecurity.io/advisories/118 Description: Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(path, pattern)` in Minimatch 3.0.1 and earlier is vulnerable to ReDoS in the `pattern` parameter. Ubuntu-Description: It was discovered that Minimatch did not perform necessary bounds checking on regular expressions. An attacker could use this vulnerability to cause a denial of service. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: mikesalvatore CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_node-minimatch: upstream: https://github.com/isaacs/minimatch/commit/6944abf9e0694bd22fd9dad293faa40c2bc8a955 upstream_node-minimatch: released (3.0.4) precise/esm_node-minimatch: DNE trusty_node-minimatch: ignored (out of standard support) trusty/esm_node-minimatch: released (0.2.12-1ubuntu0.1~esm2) xenial_node-minimatch: ignored (end of standard support, was needed) artful_node-minimatch: ignored (reached end-of-life) bionic_node-minimatch: not-affected (3.0.4-3) cosmic_node-minimatch: not-affected (3.0.4-3) disco_node-minimatch: not-affected (3.0.4-3) eoan_node-minimatch: not-affected (3.0.4-3) focal_node-minimatch: not-affected (3.0.4-3) groovy_node-minimatch: not-affected (3.0.4-3) hirsute_node-minimatch: not-affected (3.0.4-3) impish_node-minimatch: not-affected (3.0.4-3) jammy_node-minimatch: not-affected (3.0.4-3) devel_node-minimatch: not-affected (3.0.4-3)