The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
2017-01-23T21:59:01.330
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | momentjs | moment | < 2.11.2 | Yes |
Application | tenable | nessus | ≤ 8.2.3 | Yes |
Application | oracle | primavera_unifier | ≤ 18.8.4 | Yes |