PT-2019-11537 · Lodash · Lodash

Cristianstaicu

·

Publicado

2019-07-17

·

Atualizado

2020-09-30

·

CVE-2019-1010266

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: lodash versions prior to 4.17.11
Description: The issue is related to uncontrolled resource consumption, which can lead to a denial of service. It affects the date handler component. An attacker can exploit this by providing very long strings that the library attempts to match using a regular expression.
Recommendations: For versions prior to 4.17.11, update to version 4.17.11 to resolve the issue. As a temporary workaround, consider restricting the input length for the date handler component to prevent very long strings from being processed.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-45159
CVE-2019-1010266
GHSA-X5RQ-J2XG-H7QM
SNYK-JS-LODASH-73639

Produtos afetados

Lodash