{"id":"GHSA-hhfg-6hfc-rvxm","summary":"Regular Expression Denial of Service in jsoneditor","details":"JSON Editor is a web-based tool to view, edit, format, and validate JSON. It has various modes such as a tree editor, a code editor, and a plain text editor. The jsoneditor package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted element as input to the getInnerText function may cause an application to consume an excessive amount of CPU. Below pinned line using vulnerable regex.","aliases":["CVE-2021-3822"],"modified":"2023-11-08T04:06:26.529779Z","published":"2021-09-29T17:15:55Z","database_specific":{"nvd_published_at":"2021-09-27T13:15:00Z","cwe_ids":["CWE-1333","CWE-400","CWE-697"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-09-28T20:52:54Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3822"},{"type":"WEB","url":"https://github.com/josdejong/jsoneditor/commit/092e386cf49f2a1450625617da8e0137ed067c3e"},{"type":"PACKAGE","url":"https://github.com/josdejong/jsoneditor"},{"type":"WEB","url":"https://huntr.dev/bounties/1e3ed803-b7ed-42f1-a4ea-c4c75da9de73"}],"affected":[{"package":{"name":"jsoneditor","ecosystem":"npm","purl":"pkg:npm/jsoneditor"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"9.5.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-hhfg-6hfc-rvxm/GHSA-hhfg-6hfc-rvxm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}