{"id":"GHSA-2pr6-76vf-7546","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2pr6-76vf-7546","summary":"Denial of Service in js-yaml","details":"Versions of `js-yaml` prior to 3.13.0 are vulnerable to Denial of Service. By parsing a carefully-crafted YAML file, the node process stalls and may exhaust system resources leading to a Denial of Service.\n\n\n## Recommendation\n\nUpgrade to version 3.13.0.","published":"2019-06-05T14:35:29Z","modified":"2021-08-04T21:32:56Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"js-yaml","fixedVersion":"3.13.0"}],"fix":{"url":"https://github.com/nodeca/js-yaml/commit/a567ef3c6e61eb319f0bfc2671d91061afb01235","label":"nodeca/js-yaml@a567ef3"},"references":[{"type":"WEB","url":"https://github.com/nodeca/js-yaml/issues/475"},{"type":"WEB","url":"https://github.com/nodeca/js-yaml/commit/a567ef3c6e61eb319f0bfc2671d91061afb01235"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-JSYAML-173999"},{"type":"WEB","url":"https://www.npmjs.com/advisories/788"},{"type":"WEB","url":"https://www.npmjs.com/advisories/788/versions"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-08-04T21:32:56Z"}}