CVE-2016-4055

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
23/01/2017
Last modified:
20/04/2025

Description

The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:momentjs:moment:*:*:*:*:*:node.js:*:* 2.11.2 (excluding)
cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:* 8.2.3 (including)
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:* 16.0 (including) 18.8.4 (including)


References to Advisories, Solutions, and Tools