Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-24785

Опубликовано: 04 апр. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

РелизСтатусПримечание
esm-apps/xenial

needed

trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

released

2.20.1+ds-1ubuntu0.1
devel

not-affected

2.29.3+ds-1
esm-apps/bionic

released

2.20.1+ds-1ubuntu0.1
esm-apps/focal

released

2.24.0+ds-2ubuntu0.1
esm-apps/jammy

released

2.29.1+ds-3ubuntu0.2
esm-apps/noble

not-affected

2.29.3+ds-1
esm-apps/xenial

needed

focal

released

2.24.0+ds-2ubuntu0.1
impish

ignored

end of life
jammy

released

2.29.1+ds-3ubuntu0.2

Показывать по

EPSS

Процентиль: 84%
0.02206
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 4 года назад

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

CVSS3: 7.5
nvd
почти 4 года назад

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

CVSS3: 7.5
debian
почти 4 года назад

Moment.js is a JavaScript date library for parsing, validating, manipu ...

CVSS3: 7.5
github
почти 4 года назад

Path Traversal: 'dir/../../filename' in moment.locale

CVSS3: 7.5
fstec
около 1 года назад

Уязвимость компонента moment.js агента скнирования RedCheck, позволяющая нарушителю получить доступ к файлам на сервере за пределами ожидаемого каталога с локализацией

EPSS

Процентиль: 84%
0.02206
Низкий

5 Medium

CVSS2

7.5 High

CVSS3