PT-2019-11537 · Lodash · Lodash
Cristianstaicu
·
Published
2019-07-17
·
Updated
2020-09-30
·
CVE-2019-1010266
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
lodash versions prior to 4.17.11
Description:
The issue is related to uncontrolled resource consumption, which can lead to a denial of service. It affects the date handler component. An attacker can exploit this by providing very long strings that the library attempts to match using a regular expression.
Recommendations:
For versions prior to 4.17.11, update to version 4.17.11 to resolve the issue. As a temporary workaround, consider restricting the input length for the date handler component to prevent very long strings from being processed.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lodash