Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-10539

Опубликовано: 31 мая 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:negotiator_project:negotiator:*:*:*:*:*:node.js:*:*
Версия до 0.6.0 (включая)

EPSS

Процентиль: 55%
0.00328
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400
CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.

CVSS3: 7.5
debian
больше 7 лет назад

negotiator is an HTTP content negotiator for Node.js and is used by ma ...

github
больше 7 лет назад

Regular Expression Denial of Service in negotiator

EPSS

Процентиль: 55%
0.00328
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400
CWE-20