CVE-2017-20165
A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to version 3.1.0 is able to address this issue. The identifier of the patch is c38a0166c266a679c8de012d4eaccec3f944e685. It is recommended to upgrade the affected component. The identifier VDB-217665 was assigned to this vulnerability.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1333
- Affected
- debug project/debug
- Source
- cna@vuldb.com
References
- https://github.com/debug-js/debug/commit/c38a0166c266a679c8de012d4eaccec3f944e685Patch
- https://github.com/debug-js/debug/pull/504Patch
- https://github.com/debug-js/debug/releases/tag/3.1.0Release Notes
- https://vuldb.com/?ctiid.217665Third Party Advisory, VDB Entry
- https://vuldb.com/?id.217665Third Party Advisory, VDB Entry
- https://github.com/debug-js/debug/commit/c38a0166c266a679c8de012d4eaccec3f944e685Patch
- https://github.com/debug-js/debug/pull/504Patch
- https://github.com/debug-js/debug/releases/tag/3.1.0Release Notes
- https://vuldb.com/?ctiid.217665Third Party Advisory, VDB Entry
- https://vuldb.com/?id.217665Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.