Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18214

Опубликовано: 08 сент. 2017
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

Отчет

This issue affects the versions of momentjs as shipped with Red Hat Enterprise Satellite 5. Red Hat Product Security has rated this issue as having security impact of Moderate. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. In Quay 3.10 and above, no version of affected momentjs is present.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Mobile Application Platform 4nodejs-momentAffected
Red Hat Quay 3quay/quay-rhel8Not affected
Red Hat Satellite 5momentjsWill not fix
Red Hat JBoss Enterprise Application Platform 7nodejs-momentFixedRHSA-2023:055631.01.2023
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-hal-consoleFixedRHSA-2023:055331.01.2023
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9eap7-hal-consoleFixedRHSA-2023:055431.01.2023
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7eap7-hal-consoleFixedRHSA-2023:055231.01.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1553413nodejs-moment: Regular expression denial of service

EPSS

Процентиль: 55%
0.00322
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

CVSS3: 7.5
nvd
больше 7 лет назад

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

CVSS3: 7.5
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
больше 7 лет назад

The moment module before 2.19.3 for Node.js is prone to a regular expr ...

CVSS3: 7.5
github
больше 7 лет назад

Regular Expression Denial of Service in moment

EPSS

Процентиль: 55%
0.00322
Низкий

5.3 Medium

CVSS3