Vulnerability CVE-2020-26289


Published: 2020-12-28

Description:
date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.

Type:

CWE-400

(Uncontrolled Resource Consumption ('Resource Exhaustion'))

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Date-and-time project -> Date-and-time 

 References:
https://github.com/knowledgecode/date-and-time/commit/9e4b501eacddccc8b1f559fb414f48472ee17c2a
https://github.com/knowledgecode/date-and-time/security/advisories/GHSA-r92x-f52r-x54g
https://www.npmjs.com/package/date-and-time

Copyright 2024, cxsecurity.com

 

Back to Top