Vulnerabilities > CVE-2015-8858 - Resource Management Errors vulnerability in Uglifyjs Project Uglifyjs

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
uglifyjs-project
CWE-399

Summary

The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."

Vulnerable Configurations

Part Description Count
Application
Uglifyjs_Project
80

Common Weakness Enumeration (CWE)