Skip to content

CVE-2022-24785 @ Npm-moment-2.29.1 #20

@YSLCx

Description

@YSLCx

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2022-24785
Checkmarx Project: YSLCx/Github_demo
Repository URL: https://github.com/YSLCx/Github_demo
Branch: main
Scan ID: f799fc13-25e4-479c-a802-e1aeacbb3e2d


Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: NONE
Remediation Upgrade Recommendation: 2.29.4

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions