Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

date-and-time dependency security issue #1123

Open
zfan40 opened this issue Jun 15, 2021 · 2 comments
Open

date-and-time dependency security issue #1123

zfan40 opened this issue Jun 15, 2021 · 2 comments

Comments

@zfan40
Copy link

zfan40 commented Jun 15, 2021

问题描述:
vulnerability: date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2. remediation: Upgrade date-and-time from 0.12.0 to 0.14.2 to fix the vulnerability. vulnerability: Due to an overly permissive regular expression, the parsing of certain date strings may lead to a denial of service. remediation: Upgrade to version v0.14.2 vulnerability: date-and-time is vulnerable to Regular Expression Denial Of Service (ReDoS). The vulnerability is possible due to an overly permissive regular expression, the parsing of certain date strings may lead to a denial of service.

解决方案:
[email protected]
需要将依赖调整为^0.14.2

@zfan40
Copy link
Author

zfan40 commented Jun 15, 2021

@git-qfzhang 能不能麻烦您帮助跟进一下,感谢

@zfan40
Copy link
Author

zfan40 commented Jun 17, 2021

duplicated with #1075

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant