Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r92x-f52r-x54g

Опубликовано: 24 дек. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

regular expression denial of service (ReDoS)

date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.

Пакеты

Наименование

date-and-time

npm
Затронутые версииВерсия исправления

< 0.14.2

0.14.2

EPSS

Процентиль: 67%
0.00526
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
redhat
около 5 лет назад

date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.

CVSS3: 7.5
nvd
около 5 лет назад

date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.

EPSS

Процентиль: 67%
0.00526
Низкий

7.5 High

CVSS3

Дефекты

CWE-400