CVE-2015-8855
CVE Details
Last Update
9/25/24
NIST CVE Summary
The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."
Our Official Summary
This is a false positive as the CVE is in a node.js package that has the same name which is being used in the Golang application.
CVE Severity
Status
Ongoing
Affected Products & Versions
- Palette VerteX airgap 4.4.11
Revision History
- 1.0 07/31/2024 Initial Publication
- 2.0 08/17/2024 Remediated in Palette VerteX airgap 4.4.14
- 3.0 09/25/2024 Remediated in Palette VerteX airgap 4.4.18