Описание
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
Ссылки
- Mailing ListThird Party Advisory
- PatchThird Party Advisory
- Third Party AdvisoryVDB Entry
- Broken LinkExploitVendor Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
- PatchThird Party Advisory
- Third Party AdvisoryVDB Entry
- Broken LinkExploitVendor Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
EPSS
6.5 Medium
CVSS3
7.8 High
CVSS2
Дефекты
Связанные уязвимости
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
The duration function in the moment package before 2.11.2 for Node.js ...
EPSS
6.5 Medium
CVSS3
7.8 High
CVSS2