Description
date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.
Recommendation
Update the date-and-time package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.14.2
- Patched version(s): 0.14.2
References
Related Issues
- Regular Expression Denial of Service (ReDoS) in lodash - lodash.trimend - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash - lodash.trim - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash - CVE-2020-28500
- Regular Expression Denial of Service (ReDoS) in lodash - lodash-es - CVE-2020-28500
You might also like:
- Tags:
- npm
- date-and-time
Anything's wrong? Let us know Last updated on February 01, 2023


