-
Bug
-
Resolution: Fixed
-
Low
-
3.14.0
-
Severity 2 - Major
-
0
-
The version of moment.js used in Jira Service Desk Server before version 4.0.0 allows remote attackers to cause a denial of service in user's browsers via a regular expression denial of service. For additional details see https://github.com/moment/moment/issues/2936.
- relates to
-
JRASERVER-69040 The version of moment.js used in Jira was vulnerable to a regular expression denial of service
-
- Closed
-
[JSDSERVER-6289] The version of moment.js used in Jira Service Desk was vulnerable to a regular expression denial of service
Description |
Original:
Component in before version 4.0.0 allows remote attackers to IMPACT via a VULN_INFO.
The version of moment.js used in Jira Service Desk Server before version 4.0.0 allows remote attackers to cause a denial of service in user's browsers via a regular expression denial of service. For additional details see [https://github.com/moment/moment/issues/2936.|https://github.com/moment/moment/issues/2936] |
New:
The version of moment.js used in Jira Service Desk Server before version 4.0.0 allows remote attackers to cause a denial of service in user's browsers via a regular expression denial of service. For additional details see [https://github.com/moment/moment/issues/2936.|https://github.com/moment/moment/issues/2936] |
UIS | New: 0 |
Workflow | Original: JSD Bug Workflow v5 - TEMP [ 3122115 ] | New: JAC Bug Workflow v3 [ 3125943 ] |
Status | Original: Done [ 10044 ] | New: Closed [ 6 ] |
Link | New: This issue is detailed by JSDSERVER-5963 [ JSDSERVER-5963 ] |
Link |
New:
This issue relates to |
Labels | Original: advisory advisory-released cvss-medium security | New: advisory advisory-released cvss-medium patch-management security |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Untriaged [ 11672 ] | New: Done [ 10044 ] |
Security | Original: Atlassian Staff [ 10750 ] |
Labels | Original: advisory advisory-to-release cvss-medium exclude-from-security-metrics-page security | New: advisory advisory-released cvss-medium security |
Description | Original: Component in Atlassian JIRA Service Desk Server from version 3.14.0 before version 4.0.0 allows remote attackers to IMPACT via a VULN_INFO. |
New:
Component in before version 4.0.0 allows remote attackers to IMPACT via a VULN_INFO.
The version of moment.js used in Jira Service Desk Server before version 4.0.0 allows remote attackers to cause a denial of service in user's browsers via a regular expression denial of service. For additional details see [https://github.com/moment/moment/issues/2936.|https://github.com/moment/moment/issues/2936] |