First published: Thu Jun 07 2018(Updated: )
Affected versions of `fresh` are vulnerable to regular expression denial of service when parsing specially crafted user input. ## Recommendation Update to version 0.5.2 or later.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/fresh | <0.5.2 | 0.5.2 |
Fresh Project Fresh | <0.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16119 is a vulnerability in the Fresh module used by the Express.js framework for HTTP response freshness testing.
The severity of CVE-2017-16119 is high with a CVSS score of 7.5.
CVE-2017-16119 affects versions of Fresh up to and excluding 0.5.2.
CVE-2017-16119 can cause a denial of service condition by blocking the event loop.
To fix CVE-2017-16119, update Fresh to version 0.5.2 or higher.