CVE-2017-20165
low-risk
Published 2023-01-09
A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to version 3.1.0 is able to address this issue. The identifier of the patch is c38a0166c266a679c8de012d4eaccec3f944e685. It is recommended to upgrade the affected component. The identifier VDB-217665 was assigned to this vulnerability.
Do I need to act?
~
1.6% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.5/10
Low
ADJACENT_NETWORK
/ LOW complexity
Affected Products (1)
Debug
Affected Vendors
References (10)
Release Notes
https://github.com/debug-js/debug/releases/tag/3.1.0
Third Party Advisory
https://vuldb.com/?ctiid.217665
Third Party Advisory
https://vuldb.com/?id.217665
Release Notes
https://github.com/debug-js/debug/releases/tag/3.1.0
Third Party Advisory
https://vuldb.com/?ctiid.217665
Third Party Advisory
https://vuldb.com/?id.217665
22
/ 100
low-risk
Severity
13/34 · Low
Exploitability
4/34 · Minimal
Exposure
5/34 · Minimal