You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
Source: node-moment
Version: 2.29.1+ds-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: car...@debian.org, Debian Security Team <te...@security.debian.org>
Control: found -1 2.29.1+ds-2
Control: found -1 2.24.0+ds-1
Hi,
The following vulnerability was published for node-moment.
CVE-2022-24785[0]:
| Moment.js is a JavaScript date library for parsing, validating,
| manipulating, and formatting dates. A path traversal vulnerability
| impacts npm (server) users of Moment.js between versions 1.0.1 and
| 2.29.1, especially if a user-provided locale string is directly used
| to switch moment locale. This problem is patched in 2.29.2, and the
| patch can be applied to all affected versions. As a workaround,
| sanitize the user-provided locale name before passing it to Moment.js.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.