Vulnerability Database

289,697

Total vulnerabilities in the database

Moderate severity vulnerability that affects moment

Withdrawn, accidental duplicate publish.

The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."

No technical information available.

No CWE or OWASP classifications available.

Software From Fixed in
moment - 2.11.2

No references available.