Vulnerability Description
The is-my-json-valid package before 2.12.4 for Node.js has an incorrect exports['utc-millisec'] regular expression, which allows remote attackers to cause a denial of service (blocked event loop) via a crafted string.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Is My Json Valid Project | Is My Json Valid | <= 2.12.3 |
Related Weaknesses (CWE)
References
- https://github.com/mafintosh/is-my-json-valid/commit/eca4beb21e61877d76fdf6bea77Patch
- https://nodesecurity.io/advisories/76
- https://github.com/mafintosh/is-my-json-valid/commit/eca4beb21e61877d76fdf6bea77Patch
- https://nodesecurity.io/advisories/76
FAQ
What is CVE-2016-2537?
CVE-2016-2537 is a vulnerability with a CVSS score of 7.5 (HIGH). The is-my-json-valid package before 2.12.4 for Node.js has an incorrect exports['utc-millisec'] regular expression, which allows remote attackers to cause a denial of service (blocked event loop) via ...
How severe is CVE-2016-2537?
CVE-2016-2537 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2537?
Check the references section above for vendor advisories and patch information. Affected products include: Is My Json Valid Project Is My Json Valid.