CVE-2017-16116
Summary
| CVE | CVE-2017-16116 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-07 02:29:00 UTC |
| Updated | 2019-10-09 23:24:00 UTC |
| Description | The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of service when specifically crafted untrusted user input is passed into the underscore or unescapeHTML methods. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Overview |
MISC |
nodesecurity.io |
Patch, Third Party Advisory |
| Vulnerable Regular Expressions · Issue #212 · jprichardson/string.js · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983955 Nodejs (npm) Security Update for string (GHSA-g36h-6r4f-3mqp)