CVE-2020-26289
28.12.2020, 19:15
date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.Enginsight
Vendor | Product | Version |
---|---|---|
date-and-time_project | date-and-time | 𝑥 < 0.14.2 |
𝑥
= Vulnerable software versions
References