脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
N/A
脆弱性説明
Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
脆弱性タイプ
CWE-1333
脆弱性タイトル
pacote 安全漏洞
脆弱性説明
pacote是npm开源的一个从npm仓库获取包清单和压缩包的工具。 pacote 11.2.7版本存在安全漏洞,该漏洞源于addGitSha函数可能导致拒绝服务,攻击者可以通过提供特制的spec.rawSpec值触发函数正则替换和字符串操作逻辑,造成CPU过度消耗。
CVSS情報
N/A
脆弱性タイプ
N/A