Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-24785

Опубликовано: 04 апр. 2022
Источник: debian
EPSS Низкий

Описание

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-momentfixed2.29.2+ds-1package
node-momentfixed2.29.1+ds-2+deb11u1bullseyepackage
node-momentend-of-lifestretchpackage

Примечания

  • https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4

  • https://github.com/moment/moment/commit/4211bfc8f15746be4019bba557e29a7ba83d54c5 (2.29.2)

EPSS

Процентиль: 84%
0.02206
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

CVSS3: 7.5
redhat
почти 4 года назад

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

CVSS3: 7.5
nvd
почти 4 года назад

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

CVSS3: 7.5
github
почти 4 года назад

Path Traversal: 'dir/../../filename' in moment.locale

CVSS3: 7.5
fstec
около 1 года назад

Уязвимость компонента moment.js агента скнирования RedCheck, позволяющая нарушителю получить доступ к файлам на сервере за пределами ожидаемого каталога с локализацией

EPSS

Процентиль: 84%
0.02206
Низкий