REDHAT-BUG-2442922: Medium severity npm/minimatch vulnerability
minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested () extglobs produce regexps with nested unbounded quantifiers (e.g. (?:(?:a|b))), which exhibit catastrophic backtracking in V8. With a 12-byte pattern (((a|b))) and an 18-byte non-matching input, minimatch() stalls for over 7 seconds. Adding a single nesting level or a few input characters pushes this to minutes. This is the most severe finding: it is triggered by the default minimatch() API with no special options, and the minimum viable pattern is only 12 bytes. The same issue affects +() extglobs equally. Versions 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4 fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.4.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.1.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.2.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.1.4