Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU21762
Risk: Medium
CVSSv4.0: 5.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/U:Green]
CVE-ID: CVE-2016-4055
CWE-ID:
CWE-399 - Resource Management Errors
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.
The vulnerability exists due to an error in the "moment.duration()" function. A remote attacker can send a specially crafted input and cause regular expression denial of service via a long string.
MitigationInstall updates from vendor's website.
Vulnerable software versionsMoment: 0.3.0 - 2.11.2
CPE2.3https://nodesecurity.io/advisories/55
https://www.npmjs.com/advisories/55
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.