Asymmetric denial of service In node-lodash
Description
Regular Expression Denial of Service (ReDoS) in lodash lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 4.17.11+dfsg-1 | ||
debian 11 | 4.17.11+dfsg-1 | ||
npm | 4.17.11 | ||
rubygems | 4.17.11 | ||
npm | 4.17.11 | ||
npm | 4.17.11 | ||
debian 12 | 4.17.11+dfsg-1 | ||
debian 14 | 4.17.11+dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6.