Red Hat Bugzilla – Bug 1553413
CVE-2017-18214 nodejs-moment: Regular expression denial of service
Last modified: 2018-06-03 19:57:35 EDT
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055. Upstream patch: https://github.com/moment/moment/pull/4326 Upstream issue: https://github.com/moment/moment/issues/4163 References: https://nodesecurity.io/advisories/532
Created nodejs-moment tracking bugs for this issue: Affects: fedora-all [bug 1553414]
Statement: This issue affects the versions of momentjs as shipped with Red Hat Enterprise Satellite 5. Red Hat Product Security has rated this issue as having security impact of Moderate. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.