NodeJS/cross-spawn/5.1.0
Cross platform child_process#spawn and child_process#spawnSync
https://www.npmjs.com/package/cross-spawn
MIT
1 Security Vulnerabilities
Regular Expression Denial of Service (ReDoS) in cross-spawn
Published date: 2024-11-08T06:30:47Z
CVE: CVE-2024-21538
Links:
- https://nvd.nist.gov/vuln/detail/CVE-2024-21538
- https://github.com/moxystudio/node-cross-spawn/pull/160
- https://github.com/moxystudio/node-cross-spawn/commit/5ff3a07d9add449021d806e45c4168203aa833ff
- https://github.com/moxystudio/node-cross-spawn/commit/640d391fde65388548601d95abedccc12943374f
- https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230
- https://github.com/advisories/GHSA-3xgq-45jj-v275
- https://github.com/moxystudio/node-cross-spawn/issues/165
- https://github.com/moxystudio/node-cross-spawn/commit/d35c865b877d2f9ded7c1ed87521c2fdb689c8dd
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-8366349
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
Affected versions:
["0.1.0", "0.1.2", "0.1.6", "0.2.0", "0.2.1", "0.2.2", "0.2.3", "0.2.7", "0.2.8", "0.2.9", "0.3.0", "0.4.0", "1.0.0", "1.0.1", "1.0.3", "2.0.0", "2.0.1", "2.1.0", "2.1.1", "2.1.2", "2.2.2", "2.2.3", "3.0.0", "4.0.2", "5.0.1", "5.1.0", "6.0.1", "0.1.1", "0.1.3", "0.1.4", "0.1.5", "0.1.7", "0.2.4", "0.2.5", "0.2.6", "0.4.1", "1.0.2", "1.0.4", "2.1.3", "2.1.4", "2.1.5", "2.2.0", "3.0.1", "4.0.0", "5.0.0", "6.0.0", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "7.0.2", "7.0.3", "7.0.0", "7.0.1", "7.0.4"]
Secure versions:
[6.0.6, 7.0.5, 7.0.6]
Recommendation:
Update to version 7.0.6.
58 Other Versions
Version | License | Security | Released | |
---|---|---|---|---|
7.0.6 | MIT | 2024-11-18 - 13:59 | 8 months | |
7.0.5 | MIT | 2024-11-07 - 13:00 | 8 months | |
7.0.4 | MIT | 1 | 2024-11-07 - 10:50 | 8 months |
7.0.3 | MIT | 1 | 2020-05-25 - 15:35 | about 5 years |
7.0.2 | MIT | 1 | 2020-04-04 - 09:56 | over 5 years |
7.0.1 | MIT | 1 | 2019-10-07 - 09:17 | almost 6 years |
7.0.0 | MIT | 1 | 2019-09-03 - 11:45 | almost 6 years |
6.0.6 | MIT | 2024-11-18 - 14:21 | 8 months | |
6.0.5 | MIT | 1 | 2018-03-02 - 23:15 | over 7 years |
6.0.4 | MIT | 1 | 2018-01-31 - 04:49 | over 7 years |
6.0.3 | MIT | 1 | 2018-01-23 - 02:57 | over 7 years |
6.0.2 | MIT | 1 | 2018-01-23 - 02:27 | over 7 years |
6.0.1 | MIT | 1 | 2018-01-23 - 02:11 | over 7 years |
6.0.0 | MIT | 1 | 2018-01-23 - 01:23 | over 7 years |
5.1.0 | MIT | 1 | 2017-02-26 - 18:38 | over 8 years |
5.0.1 | MIT | 1 | 2016-11-04 - 23:45 | over 8 years |
5.0.0 | MIT | 1 | 2016-10-30 - 16:32 | over 8 years |
4.0.2 | MIT | 1 | 2016-09-25 - 11:43 | almost 9 years |
4.0.0 | MIT | 1 | 2016-05-26 - 20:50 | about 9 years |
3.0.1 | MIT | 1 | 2016-05-18 - 21:38 | about 9 years |
3.0.0 | MIT | 1 | 2016-05-18 - 13:15 | about 9 years |
2.2.3 | MIT | 1 | 2016-04-13 - 19:06 | over 9 years |
2.2.2 | MIT | 1 | 2016-04-08 - 21:53 | over 9 years |
2.2.0 | MIT | 1 | 2016-04-06 - 20:48 | over 9 years |
2.1.5 | MIT | 1 | 2016-01-27 - 01:15 | over 9 years |
2.1.4 | MIT | 1 | 2016-01-03 - 15:37 | over 9 years |
2.1.3 | MIT | 1 | 2016-01-02 - 15:27 | over 9 years |
2.1.2 | MIT | 1 | 2016-01-02 - 14:50 | over 9 years |
2.1.1 | MIT | 1 | 2016-01-02 - 09:57 | over 9 years |
2.1.0 | MIT | 1 | 2015-12-06 - 15:26 | over 9 years |
2.0.1 | MIT | 1 | 2015-11-29 - 17:30 | over 9 years |
2.0.0 | MIT | 1 | 2015-07-21 - 22:25 | almost 10 years |
1.0.4 | MIT | 1 | 2015-07-16 - 16:57 | almost 10 years |
1.0.3 | MIT | 1 | 2015-07-02 - 20:21 | about 10 years |
1.0.2 | MIT | 1 | 2015-07-02 - 20:15 | about 10 years |
1.0.1 | MIT | 1 | 2015-07-02 - 19:10 | about 10 years |
1.0.0 | MIT | 1 | 2015-07-02 - 19:01 | about 10 years |
0.4.1 | MIT | 1 | 2015-06-10 - 15:11 | about 10 years |
0.4.0 | MIT | 1 | 2015-05-06 - 22:21 | about 10 years |
0.3.0 | MIT | 1 | 2015-05-06 - 08:02 | about 10 years |
0.2.9 | MIT | 1 | 2015-04-08 - 16:18 | over 10 years |
0.2.8 | MIT | 1 | 2015-03-28 - 00:05 | over 10 years |
0.2.7 | MIT | 1 | 2015-03-28 - 00:03 | over 10 years |
0.2.6 | MIT | 1 | 2015-02-08 - 20:58 | over 10 years |
0.2.5 | MIT | 1 | 2015-02-08 - 20:35 | over 10 years |
0.2.4 | MIT | 1 | 2015-02-08 - 20:34 | over 10 years |
0.2.3 | MIT | 1 | 2014-08-29 - 08:12 | almost 11 years |
0.2.2 | MIT | 1 | 2014-08-28 - 22:59 | almost 11 years |
0.2.1 | MIT | 1 | 2014-08-28 - 22:50 | almost 11 years |
0.2.0 | MIT | 1 | 2014-08-28 - 22:41 | almost 11 years |