CVE-2016-2537
23.02.2016, 05:59
The is-my-json-valid package before 2.12.4 for Node.js has an incorrect exports['utc-millisec'] regular expression, which allows remote attackers to cause a denial of service (blocked event loop) via a crafted string.Enginsight
Vendor | Product | Version |
---|---|---|
is_my_json_valid_project | is_my_json_valid | 𝑥 ≤ 2.12.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration