PT-2019-11537 · Lodash · Lodash

Cristianstaicu

·

Published

2019-07-17

·

Updated

2020-09-30

·

CVE-2019-1010266

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: lodash versions prior to 4.17.11
Description: The issue is related to uncontrolled resource consumption, which can lead to a denial of service. It affects the date handler component. An attacker can exploit this by providing very long strings that the library attempts to match using a regular expression.
Recommendations: For versions prior to 4.17.11, update to version 4.17.11 to resolve the issue. As a temporary workaround, consider restricting the input length for the date handler component to prevent very long strings from being processed.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-45159
CVE-2019-1010266
GHSA-X5RQ-J2XG-H7QM
SNYK-JS-LODASH-73639

Affected Products

Lodash