Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-24785

Опубликовано: 04 апр. 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:momentjs:moment:*:*:*:*:*:node.js:*:*
Версия от 1.0.1 (включая) до 2.29.2 (исключая)
cpe:2.3:a:momentjs:moment:*:*:*:*:*:nuget:*:*
Версия от 1.0.1 (включая) до 2.29.2 (исключая)
Конфигурация 2
cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*
Версия до 5.21.0 (исключая)
Конфигурация 3

Одно из

cpe:2.3:a:netapp:active_iq:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02206
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

CVSS3: 7.5
redhat
почти 4 года назад

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

CVSS3: 7.5
debian
почти 4 года назад

Moment.js is a JavaScript date library for parsing, validating, manipu ...

CVSS3: 7.5
github
почти 4 года назад

Path Traversal: 'dir/../../filename' in moment.locale

CVSS3: 7.5
fstec
около 1 года назад

Уязвимость компонента moment.js агента скнирования RedCheck, позволяющая нарушителю получить доступ к файлам на сервере за пределами ожидаемого каталога с локализацией

EPSS

Процентиль: 84%
0.02206
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22
CWE-22