CVE-2017-18214: High severity Momentjs Moment Node.js vulnerability
Node.js moment module is vulnerable to a denial of service. A remote attacker could exploit this vulnerability to cause a low severity regular expression denial of service.
Other sources
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2017-18214.
What is the severity level of CVE-2017-18214?
The severity level of CVE-2017-18214 is high.
What is the affected software for CVE-2017-18214?
The affected software for CVE-2017-18214 is Node.js moment module before 2.19.3.
How can a remote attacker exploit CVE-2017-18214?
A remote attacker could exploit CVE-2017-18214 to cause a low severity regular expression denial of service.
Where can I find more information about CVE-2017-18214?
You can find more information about CVE-2017-18214 at the following references: [Reference 1](https://access.redhat.com/security/cve/CVE-2016-4055), [Reference 2](https://github.com/moment/moment/pull/4326), [Reference 3](https://github.com/moment/moment/issues/4163).