Executive brief
minimatch is a popular JavaScript library used for glob pattern matching in file paths and text processing. The vulnerability allows an attacker to cause a denial of service by providing a specially crafted pattern that triggers excessive CPU consumption via catastrophic backtracking in the regular expression engine, potentially freezing or crashing applications that rely on this library.
Technical details
This is a Regular Expression Denial of Service (ReDoS) vulnerability in the minimatch library's pattern matching logic. The vulnerability exists when user-controlled input is passed to the pattern argument of the minimatch(path, pattern) function. An attacker can craft a malicious pattern (e.g., "[!" followed by a large number of backslashes and "A") that causes pathological backtracking in the regex engine, consuming excessive CPU resources and causing the application to hang. The vulnerability requires network access and no authentication, and affects all versions prior to 3.0.2. The patch was released in version 3.0.2.
Affected products
- npm minimatch < 3.0.2
Timeline
- 2018-10-09: disclosed
- 2018-10-09: patched: version 3.0.2