CVE-2020-1920

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/06/2021
Last modified:
06/10/2022

Description

A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:facebook:react-native:*:*:*:*:*:*:*:* 0.59.0 (including) 0.64.1 (excluding)