Vulnerabilities/

regular expression denial of service (ReDoS) (GHSA-r92x-f52r-x54g)

Severity:
High

Description

date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.

Recommendation

Update the date-and-time package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
date-and-time
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing