CVE-2016-4055

Aliases:GHSA-87vv-r9j6-g5qv
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 23 Jan 2017, 21:00
Last modified:06 Aug 2024, 00:17

Vulnerability Summary

Overall Risk (default)
medium
42/100
CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
2.71% LOW
3% probability -1.34%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

23 Jan 2017, 21:00
Published
Vulnerability first disclosed
06 Aug 2024, 00:17
Last Modified
Vulnerability information updated

Description

The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v3.0MEDIUMScore: 6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v2.0HIGHScore: 7.8AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 2.71% Percentile: 86%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • momentjsmoment

    < 2.11.2

  • Npmmoment

    < 2.11.2

  • oracleprimavera_unifier

    ≥ 16.0, ≤ 18.8.4

  • tenablenessus

    ≤ 8.2.3

References (17)