Microsoft Azure Client Library for node.

Known vulnerabilities1
Vulnerable paths3

Regular Expression Denial of Service

medium severity
  • Vulnerable module: moment
  • Introduced through: azure-monitoring@0.10.4, azure-scheduler@0.10.3 and others

Detailed paths

  • Introduced through: azure@1.2.0-preview azure-monitoring@0.10.4 moment@2.14.1
  • Introduced through: azure@1.2.0-preview azure-scheduler@0.10.3 moment@2.14.1
  • Introduced through: azure@1.2.0-preview azure-asm-website@0.10.5 moment@2.14.1


moment is a lightweight JavaScript date library for parsing, validating, manipulating, and formatting dates.

Affected versions of the package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks for any locale that has separate format and standalone options and format input can be controlled by the user.

An attacker can provide a specially crafted input to the format function, which nearly matches the pattern being matched. This will cause the regular expression matching to take a long time, all the while occupying the event loop and preventing it from processing other requests and making the server unavailable (a Denial of Service attack).

Disclosure Timeline

  • October 19th, 2016 - Reported the issue to package owner.
  • October 19th, 2016 - Issue acknowledged by package owner.
  • October 24th, 2016 - Issue fixed and version 2.15.2 released.