CVE-2020-26289

date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:date-and-time_project:date-and-time:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 05:19

Type Values Removed Values Added
References () https://github.com/knowledgecode/date-and-time/commit/9e4b501eacddccc8b1f559fb414f48472ee17c2a - Patch, Third Party Advisory () https://github.com/knowledgecode/date-and-time/commit/9e4b501eacddccc8b1f559fb414f48472ee17c2a - Patch, Third Party Advisory
References () https://github.com/knowledgecode/date-and-time/security/advisories/GHSA-r92x-f52r-x54g - Third Party Advisory () https://github.com/knowledgecode/date-and-time/security/advisories/GHSA-r92x-f52r-x54g - Third Party Advisory
References () https://www.npmjs.com/package/date-and-time - Product, Third Party Advisory () https://www.npmjs.com/package/date-and-time - Product, Third Party Advisory

Information

Published : 2020-12-28 19:15

Updated : 2024-11-21 05:19


NVD link : CVE-2020-26289

Mitre link : CVE-2020-26289

CVE.ORG link : CVE-2020-26289


JSON object : View

Products Affected

date-and-time_project

  • date-and-time
CWE
CWE-400

Uncontrolled Resource Consumption