Vulnerabilities > CVE-2015-8858 - Resource Management Errors vulnerability in Uglifyjs Project Uglifyjs

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
uglifyjs-project
CWE-399

Summary

The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."

Vulnerable Configurations

Part Description Count
Application
Uglifyjs_Project
1

Common Weakness Enumeration (CWE)