Описание
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
node-moment | fixed | 2.19.3+ds-1 | package |
Примечания
fixed in 2.19.3 upstream
https://github.com/moment/moment/commit/69ed9d44957fa6ab12b73d2ae29d286a857b80eb
https://github.com/moment/moment/pull/4326
https://github.com/moment/moment/issues/4163
https://nodesecurity.io/advisories/532
nodejs not covered by security support
EPSS
Связанные уязвимости
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
EPSS