7.8
CVSSv2

CVE-2015-8315

Published: 23/01/2017 Updated: 08/02/2024
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The ms package prior to 0.7.1 for Node.js allows malicious users to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vercel ms

Vendor Advisories

The ms package before 071 for Nodejs allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)" ...

Github Repositories

fake-vulnerabilities-js-npm Example npm repository containing fake data with vulnerable dependencies It should report at least: CVE-2015-8315 in module "ms" (nodesecurityio/advisories/46) $ nsp check --output summary (+) 1 vulnerabilities found Name Installed Patched Path More Info ms 070 >070