PT-2019-11537 · Lodash · Lodash
Cristianstaicu
·
Publicado
2019-07-17
·
Atualizado
2020-09-30
·
CVE-2019-1010266
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
lodash versions prior to 4.17.11
Description:
The issue is related to uncontrolled resource consumption, which can lead to a denial of service. It affects the date handler component. An attacker can exploit this by providing very long strings that the library attempts to match using a regular expression.
Recommendations:
For versions prior to 4.17.11, update to version 4.17.11 to resolve the issue. As a temporary workaround, consider restricting the input length for the date handler component to prevent very long strings from being processed.
Exploit
Correção
DoS
Allocation of Resources Without Limits
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lodash