{"id":"GHSA-hxf5-mg84-pj4m","summary":"Moderate severity vulnerability that affects moment","details":"Withdrawn, accidental duplicate publish.\n\nThe duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a \"regular expression Denial of Service (ReDoS).\"","modified":"2020-06-17T15:14:53Z","published":"2018-07-31T23:03:17Z","withdrawn":"2020-06-17T15:14:53Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-17T15:14:53Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-4055"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hxf5-mg84-pj4m"}],"affected":[{"package":{"name":"moment","ecosystem":"npm","purl":"pkg:npm/moment"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.11.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-hxf5-mg84-pj4m/GHSA-hxf5-mg84-pj4m.json"}}],"schema_version":"1.9.0"}