Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-18214

Опубликовано: 04 мар. 2018
Источник: debian
EPSS Низкий

Описание

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-momentfixed2.19.3+ds-1package

Примечания

  • fixed in 2.19.3 upstream

  • https://github.com/moment/moment/commit/69ed9d44957fa6ab12b73d2ae29d286a857b80eb

  • https://github.com/moment/moment/pull/4326

  • https://github.com/moment/moment/issues/4163

  • https://nodesecurity.io/advisories/532

  • nodejs not covered by security support

EPSS

Процентиль: 55%
0.00322
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

CVSS3: 5.3
redhat
почти 8 лет назад

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

CVSS3: 7.5
nvd
больше 7 лет назад

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

CVSS3: 7.5
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 7.5
github
больше 7 лет назад

Regular Expression Denial of Service in moment

EPSS

Процентиль: 55%
0.00322
Низкий