First published: Tue Jun 01 2021(Updated: )
A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook React-native | >=0.59.0<0.64.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1920 is a regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function in react-native.
Exploiting CVE-2020-1920 can cause the application to use excessive resources, become unresponsive, or crash.
CVE-2020-1920 affects react-native versions 0.59.0 to 0.64.0 (excluding 0.64.1).
To fix CVE-2020-1920, update react-native to version 0.64.1 or higher.
Yes, CVE-2020-1920 is classified as a high severity vulnerability with a severity score of 7.5.