You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop for around 10 seconds.
CVE-2017-16115 - High Severity Vulnerability
A JavaScript TimeSpan library for node.js (and soon the browser)
path: /tmp/git/angularjs-sample/node_modules/timespan/package.json
Library home page: http://registry.npmjs.org/timespan/-/timespan-2.3.0.tgz
Dependency Hierarchy:
The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop for around 10 seconds.
Publish Date: 2018-06-07
URL: CVE-2017-16115
Base Score Metrics:
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: