Description
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
Remediation
References
Related Vulnerabilities
Java Unspesificed Vulnerability (CVE-2018-3157)
Drupal Core 6.x Multiple Vulnerabilities (6.0 - 6.13)
Oracle HTTP Server NULL Pointer Dereference Vulnerability (CVE-2020-1971)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9517)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cross-Site Scripting (2.3.0)