HIGH 7.5 npm
Regular Expression Denial of Service in moment
GHSA-446m-mv8f-q348 · CVE-2017-18214
Published · Modified
Description
Affected versions of moment are vulnerable to a low severity regular expression denial of service when parsing dates as strings.
Recommendation
Update to version 2.19.3 or later.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2017-18214
- WEB https://github.com/moment/moment/issues/4163
- WEB https://github.com/moment/moment/pull/4326
- WEB https://github.com/moment/moment/commit/69ed9d44957fa6ab12b73d2ae29d286a857b80eb
- ADVISORY https://github.com/advisories/GHSA-446m-mv8f-q348
- PACKAGE https://github.com/moment/moment
- WEB https://www.npmjs.com/advisories/532
- WEB https://www.tenable.com/security/tns-2019-02
Ready to move
Start Securing
Free, no credit card | First findings in minutes