GHSA-g36h-6r4f-3mqp
HIGHCVE-2017-16116Affected versions of string are vulnerable to regular expression denial of service when specifically crafted untrusted user input is passed into the underscore or unescapeHTML methods.
- Affected
- <= 3.3.3
- Fixed in
- not stated
- Weakness
- CWE-400
- Published
- 2018-07-24
- Source
- github