1{
2 "ok": false,
3 "issues": {
4 "vulnerabilities": [
5 {
6 "id": "npm:ms:20170412",
7 "url": "https://snyk.io/vuln/npm:ms:20170412",
8 "title": "Regular Expression Denial of Service (ReDoS)",
9 "type": "vuln",
10 "description": "## Overview\n[`ms`](https://www.npmjs.com/package/ms) is a tiny millisecond conversion utility.\n\nAffected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to an incomplete fix for previously reported vulnerability [npm:ms:20151024](https://snyk.io/vuln/npm:ms:20151024). The fix limited the length of accepted input string to 10,000 characters, and turned to be insufficient making it possible to block the event loop for 0.3 seconds (on a typical laptop) with a specially crafted string passed to `ms()` function.\n\n*Proof of concept*\n```js\nms = require('ms');\nms('1'.repeat(9998) + 'Q') // Takes about ~0.3s\n```\n\n**Note:** Snyk's patch for this vulnerability limits input length to 100 characters. This new limit was deemed to be a breaking change by the author.\nBased on user feedback, we believe the risk of breakage is _very_ low, while the value to your security is much greater, and therefore opted to still capture this change in a patch for earlier versions as well. Whenever patching security issues, we always suggest to run tests on your code to validate that nothing has been broken.\n\nFor more information on `Regular Expression Denial of Service (ReDoS)` attacks, go to our [blog](https://snyk.io/blog/redos-and-catastrophic-backtracking/).\n\n## Disclosure Timeline\n- Feb 9th, 2017 - Reported the issue to package owner.\n- Feb 11th, 2017 - Issue acknowledged by package owner.\n- April 12th, 2017 - Fix PR opened by Snyk Security Team.\n- May 15th, 2017 - Vulnerability published.\n- May 16th, 2017 - Issue fixed and version `2.0.0` released.\n- May 21th, 2017 - Patches released for versions `>=0.7.1, <=1.0.0`.\n\n## Remediation\nUpgrade `ms` to version 2.0.0 or higher.\n\n## References\n- [GitHub PR](https://github.com/zeit/ms/pull/89)\n- [GitHub Commit](https://github.com/zeit/ms/pull/89/commits/305f2ddcd4eff7cc7c518aca6bb2b2d2daad8fef)\n",
11 "from": [
12 "mongoose@4.2.4",
13 "mquery@1.6.3",
14 "debug@2.2.0",
15 "ms@0.7.1"
16 ],
17 "package": "ms",
18 "version": "0.7.1",
19 "severity": "low",
20 "language": "js",
21 "packageManager": "npm",
22 "semver": {
23 "unaffected": ">=2.0.0",
24 "vulnerable": "<2.0.0"
25 },
26 "publicationTime": "2017-05-15T06:02:45.497Z",
27 "disclosureTime": "2017-04-11T21:00:00.000Z",
28 "isUpgradable": true,
29 "isPatchable": true,
30 "identifiers": {
31 "CVE": [],
32 "CWE": [
33 "CWE-400"
34 ],
35 "ALTERNATIVE": [
36 "SNYK-JS-MS-10509"
37 ]
38 },
39 "credit": [
40 "Snyk Security Research Team"
41 ],
42 "CVSSv3": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
43 "cvssScore": 3.7,
44 "patches": [
45 {
46 "id": "patch:npm:ms:20170412:0",
47 "urls": [
48 "https://s3.amazonaws.com/snyk-rules-pre-repository/snapshots/develop/patches/npm/ms/20170412/ms_100.patch"
49 ],
50 "version": "=1.0.0",
51 "comments": [],
52 "modificationTime": "2017-05-16T10:12:18.990Z"
53 },
54 {
55 "id": "patch:npm:ms:20170412:1",
56 "urls": [
57 "https://s3.amazonaws.com/snyk-rules-pre-repository/snapshots/develop/patches/npm/ms/20170412/ms_072-073.patch"
58 ],
59 "version": "=0.7.2 || =0.7.3",
60 "comments": [],
61 "modificationTime": "2017-05-16T10:12:18.990Z"
62 },
63 {
64 "id": "patch:npm:ms:20170412:2",
65 "urls": [
66 "https://s3.amazonaws.com/snyk-rules-pre-repository/snapshots/develop/patches/npm/ms/20170412/ms_071.patch"
67 ],
68 "version": "=0.7.1",
69 "comments": [],
70 "modificationTime": "2017-05-16T10:12:18.990Z"
71 }
72 ],
73 "isIgnored": true,
74 "isPatched": false,
75 "upgradePath": [
76 "mongoose@4.10.2",
77 "mquery@2.3.1",
78 "debug@2.6.8",
79 "ms@2.0.0"
80 ]
81 }
82 ],
83 "licenses": []
84 },
85 "dependencyCount": 250,
86 "packageManager": "npm"
87}