First published: Fri May 28 2021(Updated: )
@rkesters/gnuplot is an easy to use node module to draw charts using gnuplot and ps2pdf. The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the `.end()` method.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/trim-newlines | =4.0.0 | 4.0.1 |
npm/trim-newlines | <3.0.1 | 3.0.1 |
Trim-newlines Project Trim-newlines | <3.0.1 | |
Trim-newlines Project Trim-newlines | >=4.0.0<4.0.1 | |
Netapp E-series Performance Analyzer | ||
Debian Debian Linux | =10.0 | |
redhat/ovirt-web-ui | <0:1.9.0-1.el8e | 0:1.9.0-1.el8e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-33623.
The severity of CVE-2021-33623 is high.
CVE-2021-33623 has an issue related to regular expression denial-of-service (ReDoS) for the `.end()` method in Node.js.
Version 4.0.0 and versions before 4.0.1 of trim-newlines for Node.js are affected by CVE-2021-33623.
To fix CVE-2021-33623, update trim-newlines to version 4.0.1 or newer.