CVE-2016-4055Uncontrolled Resource Consumption in Moment

Severity
6.5MEDIUMNVD
EPSS
2.7%
top 14.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateMar 15

Description

The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

npmmoment/moment< 2.11.2
NVDmomentjs/moment< 2.11.2
NVDtenable/nessus8.2.3
NVDoracle/primavera_unifier16.018.8.4

Patches

🔴Vulnerability Details

4
GHSA
Regular Expression Denial of Service in moment2017-10-24
OSV
Regular Expression Denial of Service in moment2017-10-24
CVEList
CVE-2016-4055: The duration function in the moment package before 22017-01-23
OSV
CVE-2016-4055: The duration function in the moment package before 22017-01-23

📋Vendor Advisories

5
Ubuntu
Moment.js vulnerabilities2021-03-15
Microsoft
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string a different vulnerability than CVE-2016-4055.2018-03-13
Red Hat
nodejs-moment: Regular expression denial of service2017-09-08
Red Hat
moment.js: regular expression denial of service2016-01-26
Debian
CVE-2016-4055: node-moment - The duration function in the moment package before 2.11.2 for Node.js allows rem...2016

💬Community

3
Bugzilla
CVE-2017-18214 nodejs-moment: Regular expression denial of service2018-03-08
Bugzilla
CVE-2016-4055 moment.js: regular expression denial of service2016-02-04
Bugzilla
CVE-2016-4055 nodejs-moment: moment.js: regular expression denial of service [fedora-all]2016-02-04
CVE-2016-4055 — Uncontrolled Resource Consumption | cvebase