CVE-2016-1000023: High severity Minimatch minimatch vulnerability
REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10540. Reason: This candidate is a reservation duplicate of CVE-2016-10540. Notes: All CVE users should reference CVE-2016-10540 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Other sources
Minimatch is vulnerable to a denial of service, caused by a regular expression of minimatch.js. By using a specially crafted glob pattern, a remote attacker could exploit this vulnerability to cause the application to consume an overly large amount of CPU resources
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-1000023?
CVE-2016-1000023 is a vulnerability in the minimatch.js library that can lead to denial of service attacks.
What is the severity of CVE-2016-1000023?
CVE-2016-1000023 has a severity rating of 7.5 out of 10, which is considered high.
How does CVE-2016-1000023 lead to a denial of service?
CVE-2016-1000023 is caused by a regular expression issue in minimatch.js, which can be exploited to crash the application or make it unresponsive.
Is there a fix available for CVE-2016-1000023?
Yes, there is a patch available for CVE-2016-1000023. It is recommended to update the affected software to the latest version to mitigate the vulnerability.
Where can I find more information about CVE-2016-1000023?
You can find more information about CVE-2016-1000023 in IBM's support page: https://www.ibm.com/support/pages/node/6843071