Uploaded image for project: 'Nuxeo Web UI'
  1. Nuxeo Web UI
  2. WEBUI-1526

[YARGS-PARSER] SRCCLR-SID-31414 | Unknown

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Web UI

      Description

      SRCCLR-SID-31414 | Unknown

      Severity : Medium

      yargs-parser is vulnerable to Regular Expression Denial of Service (ReDoS). The `isUnknownOption` function in `yargs-parser.ts` does not properly replace `-` characters from parse, allowing a malicious user to slow down or hang the application when unknown-options-as-args is set to true.

      Module : yags-parser

      nuxeo-web-ui.zip#zip:node_modules:yargs-parser

      Current Version : 20.2.4

      Recommended Version : 20.2.9 to 21.1.1

       

        Attachments

        1. CustomizedReport_Nuxeo_Web_UI_23_Sep_2024.pdf
          604 kB
          Alok Ranjan
        2. elements.png
          1.82 MB
          Alok Ranjan
        3. image-2024-05-15-16-27-56-400.png
          103 kB
          Madhur Kulshrestha
        4. Screenshot 2024-09-20 at 12.57.28 PM.png
          2.00 MB
          Alok Ranjan
        5. webui-latest.png
          1.40 MB
          Alok Ranjan

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: