Skip to content

Dependancy upgrades required to mitigate vulnerability #219

@codevalve

Description

@codevalve

Redis

Overview

In redis before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service.

redis 2.6.0 - 3.1.0

Regular Expression Denial of Service - https://npmjs.com/advisories/1662

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions