CPANSA-App-Netdisco-2022-24785-momentjs: App-Netdisco vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2022-04-04T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2022-04-04T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | 7.5 | Severity | High |
Original language | Language | en | |
Also referred to |
Vulnerability Description
Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.
Vulnerabilities
CVE-2022-24785
Vulnerability DescriptionMoment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.
Weakness | CWE-22 : Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
---|
Product status
Known affected
Product | Score | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
App-Netdisco greater than or equal 2.028008 and less than or equal 2.052002 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-App-Netdisco-2022-24785-momentjs JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2022/cpansa-app-netdisco-2022-24785-momentjs.json - https://github.com/moment/moment/commit/4211bfc8f15746be4019bba557e29a7ba83d54c5 external
https://github.com/moment/moment/commit/4211bfc8f15746be4019bba557e29a7ba83d54c5 - https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4 external
https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4 - https://www.tenable.com/security/tns-2022-09 external
https://www.tenable.com/security/tns-2022-09 - https://security.netapp.com/advisory/ntap-20220513-0006/ external
https://security.netapp.com/advisory/ntap-20220513-0006/ - CVE-2022-24785 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2022-24785
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Mon Apr 4 00:00:00 2022 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/