{"source":1113544,"name":"minimatch","dependency":"minimatch","title":"minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments","url":"https://github.com/advisories/GHSA-7r86-cg39-jmmj","severity":"high","versions":["0.0.1","0.0.2","0.0.4","0.0.5","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.2.0","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.2.9","0.2.10","0.2.11","0.2.12","0.2.13","0.2.14","0.3.0","0.4.0","1.0.0","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.0.10","3.0.0","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","4.0.0","4.1.0","4.1.1","4.2.0","4.2.1","4.2.2","4.2.3","4.2.4","4.2.5","4.2.6","5.0.0","5.0.1","5.1.0","5.1.1","5.1.2","5.1.3","5.1.4","5.1.5","5.1.6","5.1.7","5.1.8","5.1.9","6.0.0","6.0.1","6.0.2","6.0.3","6.0.4","6.1.0","6.1.1","6.1.2","6.1.3","6.1.4","6.1.5","6.1.6","6.1.7","6.1.8","6.1.9","6.1.10","6.2.0","6.2.1","6.2.2","6.2.3","7.0.0","7.0.1","7.1.0","7.1.1","7.1.2","7.1.3","7.1.4","7.2.0","7.3.0","7.4.0","7.4.1","7.4.2","7.4.3","7.4.4","7.4.5","7.4.6","7.4.7","7.4.8","7.4.9","8.0.0","8.0.1","8.0.2","8.0.3","8.0.4","8.0.5","8.0.6","8.0.7","9.0.0","9.0.1","9.0.2","9.0.3","9.0.4","9.0.5","9.0.6","9.0.7","9.0.8","9.0.9","10.0.0","10.0.1","10.0.2","10.0.3","10.1.0","10.1.1","10.1.2","10.1.3","10.2.0","10.2.1","10.2.2","10.2.3","10.2.4","10.2.5"],"vulnerableVersions":["9.0.0","9.0.1","9.0.2","9.0.3","9.0.4","9.0.5","9.0.6"],"cwe":["CWE-407"],"cvss":{"score":7.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"range":">=9.0.0 <9.0.7","id":"tJ9Z2VGWqiQfLaVKxc9K/6Rz1g70Mpl3An4UK+K1lyHdz27vYPzhMIkC4jRGAN2wpssY+8l13Ql259B6zkaX/Q=="}