CVE-2017-18214 PUBLISHED

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

EPSS 0.42% · 61.8th percentile

Risk Scores

EPSS Score
0.42%
61.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSnode-moment0, 2.10.6+dfsg-1, 2.11.0+ds-1

Timeline

References

Open in Interactive Console →