d3-color vulnerable to ReDoS
High severity
GitHub Reviewed
Published
Sep 29, 2022
to the GitHub Advisory Database
•
Updated Jan 13, 2023
Description
Published to the GitHub Advisory Database
Sep 29, 2022
Reviewed
Sep 29, 2022
Last updated
Jan 13, 2023
The d3-color module provides representations for various color spaces in the browser. Versions prior to 3.1.0 are vulnerable to a Regular expression Denial of Service. This issue has been patched in version 3.1.0. There are no known workarounds.
References