Denial of Service in ecstatic

Description

ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Not specified
Published (advisory)
2020-12-15 16:52:17 UTC
Updated
2023-01-09 05:04:08 UTC
GitHub reviewed
2020-12-15 16:52:06 UTC

EPSS Score

Score Percentile
0.44% 62.51%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-400 Uncontrolled Resource Consumption

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
npm ecstatic < 4.1.3 4.1.3

References

cvelogic Threat Intelligence