Details
Description
File Path: /var/lib/jenkins/workspace/xm_dependency-check_release_15.1/enterprise/targeting/frontend-api/package-lock.json?moment
NPM-1069972 suppress
-
-
- Impact This vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg `fr` is directly used to switch moment locale. ### Patches This problem is patched in 2.29.2, and the patch can be applied to all affected versions (from 1.0.1 up until 2.29.1, inclusive). ### Workarounds Sanitize user-provided locale name before passing it to moment.js. ### References Are there any links users can visit to find out more? ### For more information If you have any questions or comments about this advisory: * Open an issue in [moment repo](https://github.com/moment/moment)
-
Unscored:
- Severity: high
References:
- Advisory 1069972: Path Traversal: 'dir/../../filename' in moment.locale - - https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4 - https://nvd.nist.gov/vuln/detail/CVE-2022-24785 - https://github.com/moment/moment/commit/4211bfc8f15746be4019bba557e29a7ba83d54c5 - https://github.com/advisories/GHSA-8hfj-j24r-96c4
Vulnerable Software & Versions (NPM):
- cpe:2.3:a::moment:\<2.29.2:::::::