Description
date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.
Recommendation
Update the date-and-time package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.14.2
- Patched version(s): 0.14.2
References
Could your website be exposed too?
SmartScanner can check your website for regular expression denial of service (ReDoS) - date-and-time and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular Expression Denial of Service (ReDoS) in lodash - lodash.trimend - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash - lodash.trim - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash - lodash-es - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash - CVE-2020-28500


