Vulnerability GHSA-8hfj-j24r-96c4
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 years ago
April 04, 2022 at 09:25 PM UTC
Path Traversal: 'dir/../../filename' in moment.locale
1.0.0 - 2.29.1
1.0.0 - 2.29.1
Summary
Path Traversal: 'dir/../../filename' in moment.locale
Details
Impact
This vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg fr is directly used to switch moment locale.
Patches
This problem is patched in 2.29.2, and the patch can be applied to all affected versions (from 1.0.1 up until 2.29.1, inclusive).
Workarounds
Sanitize user-provided locale name before passing it to moment.js.
References
Are there any links users can visit to find out more?
For more information
If you have any questions or comments about this advisory:
- Open an issue in moment repo
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
5 hours ago
moment vulnerable to Path Traversal via crafted non-string locale name
2.29.2 - 2.30.1 GHSA-4p3w-j4w9-5jqw
2.29.2 - 2.30.1 GHSA-4p3w-j4w9-5jqw
High Risk
4 years ago
Moment.js vulnerable to Inefficient Regular Expression Complexity
2.20.0 - 2.21.0 and 2.23.0 - 2.24.0 and 2.26.0 - 2.28.0 GHSA-wc69-rhjr-hc9g
2.20.0 - 2.21.0 and 2.23.0 - 2.24.0 and 2.26.0 - 2.28.0 GHSA-wc69-rhjr-hc9g
High Risk
4 years ago
Moment.js vulnerable to Inefficient Regular Expression Complexity
2.20.0 - 2.21.0 and 2.23.0 - 2.24.0 and 2.26.0 - 2.28.0 GHSA-wc69-rhjr-hc9g
2.20.0 - 2.21.0 and 2.23.0 - 2.24.0 and 2.26.0 - 2.28.0 GHSA-wc69-rhjr-hc9g
High Risk
8 years ago
Regular Expression Denial of Service in moment
1.0.0 - 2.19.2 GHSA-446m-mv8f-q348
1.0.0 - 2.19.2 GHSA-446m-mv8f-q348
Medium Risk
8 years ago
Regular Expression Denial of Service in moment
1.0.0 - 2.11.1 GHSA-87vv-r9j6-g5qv
1.0.0 - 2.11.1 GHSA-87vv-r9j6-g5qv