7.0.3
9 years ago
1 years ago
Package is deprecated
Known vulnerabilities in the wappalyzer package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
wappalyzer is an identifies technologies on websites. It detects content management systems, ecommerce platforms, JavaScript frameworks, analytics tools and much more. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the PoC by Matheus Vrech
How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | <6.0.6 |
wappalyzer is an identifies technologies on websites. It detects content management systems, ecommerce platforms, JavaScript frameworks, analytics tools and much more. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). An attacker can make wappalyzer (all drivers, like browser extension and cli) stop working due to ReDoS in one of it's services regex. PoC by abrasax
How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | <6.0.3 |