Back to database
Schedule42High7.5VulnerabilityCVE-2017-16119No patch link observed

CVE-2017-16119 — Fresh is a module used by the Express.js framework for HTTP response freshness testing.

Published Jun 7, 2018, 02:29 AM UTCIngested 1h agoSource NVD(cve-db)CVE-2017-16119

Description

Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when it is passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5

High severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

None

Confidentiality

I

None

Integrity

A

High

Availability

Affected

Vendor
fresh project
Product
fresh

Versions

  • < 0.5.2

Stated as the source expressed them.