GHSA-3xq5-wjfh-ppjc
Luxon Inefficient Regular Expression Complexity vulnerability
Quick fix
GHSA-3xq5-wjfh-ppjc — luxon: upgrade to the fixed version with the command below.
npm install luxon@1.28.1Details
# Impact Luxon's `DateTime.fromRFC2822() has quadratic (N^2) complexity on some specific inputs. This causes a noticeable slowdown for inputs with lengths above 10k characters. Users providing untrusted data to this method are therefore vulnerable to (Re)DoS attacks.
This is the same bug as Moment's https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g
# Workarounds Limit the length of the input.
# References There is an excellent writeup of the same issue in Moment: https://github.com/moment/moment/pull/6015#issuecomment-1152961973
# Details `DateTime.fromRFC2822("(".repeat(500000))` takes a couple minutes to complete.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/moment/luxon/security/advisories/GHSA-3xq5-wjfh-ppjc[WEB]
- https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-22467[ADVISORY]
- https://github.com/moment/moment/pull/6015#issuecomment-1152961973[WEB]
- https://github.com/moment/luxon/commit/5ab3bf64a10da929a437629cdb2f059bb83212bf[WEB]
- https://github.com/moment/luxon[PACKAGE]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/44I3WAJKYXDLOVYRGMHAUXMIV4SPFXDZ[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4LIVOASKBQH7FEUI5RWM3SOHR6VK7ZZR[WEB]