logo

Database

Asymmetric denial of service In date-and-time

Description

regular expression denial of service (ReDoS) date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-N49E4 – Vulnerability | Fluid Attacks Database