PT-2017-4100 · Moment.Js+2 · Moment+2

Published

2017-09-08

·

Updated

2025-12-29

·

CVE-2017-18214

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions moment versions prior to 2.19.3
Description The issue is related to a regular expression denial of service via a crafted date string. It allows a remote attacker to cause a denial of service. The vulnerability is associated with an uncontrolled resource consumption.
Recommendations Update to version 2.19.3 or later. As a temporary workaround, consider restricting the use of date string parsing functionality in the moment module until a patch is available.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

AZL-32178
AZL-41019
BDU:2021-02952
CVE-2017-18214
GHSA-446M-MV8F-Q348
RHSA-2023:0552
RHSA-2023:0553
RHSA-2023:0554
USN-4786-1

Affected Products

Jira
Ubuntu
Moment