CVE-2017-16116

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
07/06/2018
Last modified:
09/10/2019

Description

The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of service when specifically crafted untrusted user input is passed into the underscore or unescapeHTML methods.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:string_project:string:*:*:*:*:*:node.js:*:* 0.2.1 (including)
cpe:2.3:a:string_project:string:*:*:*:*:*:node.js:*:* 0.2.2 (including) 3.3.3 (including)