Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-10539

Опубликовано: 31 мая 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.

РелизСтатусПримечание
artful

ignored

end of life
bionic

released

0.6.1-1
cosmic

released

0.6.1-1
devel

released

0.6.1-1
disco

released

0.6.1-1
eoan

released

0.6.1-1
esm-apps/bionic

released

0.6.1-1
esm-apps/focal

released

0.6.1-1
esm-apps/jammy

released

0.6.1-1
esm-apps/noble

released

0.6.1-1

Показывать по

EPSS

Процентиль: 55%
0.00328
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlier is vulnerable to Regular Expression Denial of Service via a specially crafted string.

CVSS3: 7.5
debian
больше 7 лет назад

negotiator is an HTTP content negotiator for Node.js and is used by ma ...

github
больше 7 лет назад

Regular Expression Denial of Service in negotiator

EPSS

Процентиль: 55%
0.00328
Низкий

5 Medium

CVSS2

7.5 High

CVSS3