Vulnerability GHSA-446m-mv8f-q348
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 years ago
March 05, 2018 at 06:35 PM UTC
Regular Expression Denial of Service in moment
1.0.0 - 2.19.2
1.0.0 - 2.19.2
Summary
Regular Expression Denial of Service in moment
Details
Affected versions of moment are vulnerable to a low severity regular expression denial of service when parsing dates as strings.
Recommendation
Update to version 2.19.3 or later.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
5 hours ago
moment vulnerable to Path Traversal via crafted non-string locale name
2.29.2 - 2.30.1 GHSA-4p3w-j4w9-5jqw
2.29.2 - 2.30.1 GHSA-4p3w-j4w9-5jqw
High Risk
4 years ago
Moment.js vulnerable to Inefficient Regular Expression Complexity
2.18.0 - 2.29.3 GHSA-wc69-rhjr-hc9g
2.18.0 - 2.29.3 GHSA-wc69-rhjr-hc9g
High Risk
4 years ago
Path Traversal: 'dir/../../filename' in moment.locale
1.0.0 - 2.29.1 GHSA-8hfj-j24r-96c4
1.0.0 - 2.29.1 GHSA-8hfj-j24r-96c4
Medium Risk
8 years ago
Regular Expression Denial of Service in moment
1.0.0 - 2.11.1 GHSA-87vv-r9j6-g5qv
1.0.0 - 2.11.1 GHSA-87vv-r9j6-g5qv
Impacted packages
Timeline
Published
8 years ago
March 05, 2018 at 06:35 PM UTC
Fixed (2.19.3)
8 years ago
November 29, 2017 at 04:28 PM UTC
Last Modified
2 years ago
November 08, 2023 at 03:59 AM UTC