Source: node-moment Version: 2.29.1+ds-3 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org> Control: found -1 2.29.1+ds-2 Control: found -1 2.24.0+ds-1
Hi, The following vulnerability was published for node-moment. CVE-2022-24785[0]: | Moment.js is a JavaScript date library for parsing, validating, | manipulating, and formatting dates. A path traversal vulnerability | impacts npm (server) users of Moment.js between versions 1.0.1 and | 2.29.1, especially if a user-provided locale string is directly used | to switch moment locale. This problem is patched in 2.29.2, and the | patch can be applied to all affected versions. As a workaround, | sanitize the user-provided locale name before passing it to Moment.js. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2022-24785 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24785 [1] https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4 [2] https://github.com/moment/moment/commit/4211bfc8f15746be4019bba557e29a7ba83d54c5 Regards, Salvatore