The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed. Upstream issue: https://github.com/get/parsejson/issues/4 References: https://nodesecurity.io/advisories/528
Created nodejs-parsejson tracking bugs for this issue: Affects: fedora-28 [bug 1588387]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Statement: Red Hat Quay includes the parsejson library as a build time dependency. It's included by karma for testing, and is not used as runtime.