Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Regular Expression Denial of Service (ReDoS) [High Severity -- SNYK] #4909

Closed
marcel-becker opened this issue Aug 8, 2022 · 2 comments
Closed
Labels
area: security involving vulnerabilities

Comments

@marcel-becker
Copy link

SNYK is reporting a high severity vulnerability in Mocha version > 9.2.1
It is still present in Mocha 10.0.0.
Here is the link to the vulnerability entry: https://security.snyk.io/vuln/SNYK-JS-MOCHA-2863123
This is a blocker for us.
My organization uses SNYK as a security gate and will not allow deployment containing code with dependencies flagged with high severity vulnerabilities.

Marcel

@Donglai-Zhang-asurion
Copy link

We occurred the same issue, and hope the community can help.

@ivanovSPvirtru
Copy link

Same here

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area: security involving vulnerabilities
Projects
None yet
Development

No branches or pull requests

4 participants