The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of service when specifically crafted untrusted user input is passed into the underscore or unescapeHTML methods.
References
Link Resource
https://github.com/jprichardson/string.js/issues/212 Exploit Third Party Advisory
https://nodesecurity.io/advisories/536 Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2018-04-26T00:00:00

Updated: 2018-06-07T01:57:01

Reserved: 2017-10-29T00:00:00


Link: CVE-2017-16116

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-06-07T02:29:02.863

Modified: 2019-10-09T23:24:47.643


Link: CVE-2017-16116

JSON object: View

cve-icon Redhat Information

No data.

CWE