[Pkg-javascript-devel] Bug#1009327: node-moment: CVE-2022-24785: path traversal vulnerability

Salvatore Bonaccorso carnil at debian.org
Mon Apr 11 20:17:39 BST 2022


Source: node-moment
Version: 2.29.1+ds-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Control: found -1 2.29.1+ds-2
Control: found -1 2.24.0+ds-1

Hi,

The following vulnerability was published for node-moment.

CVE-2022-24785[0]:
| Moment.js is a JavaScript date library for parsing, validating,
| manipulating, and formatting dates. A path traversal vulnerability
| impacts npm (server) users of Moment.js between versions 1.0.1 and
| 2.29.1, especially if a user-provided locale string is directly used
| to switch moment locale. This problem is patched in 2.29.2, and the
| patch can be applied to all affected versions. As a workaround,
| sanitize the user-provided locale name before passing it to Moment.js.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2022-24785
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24785
[1] https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4
[2] https://github.com/moment/moment/commit/4211bfc8f15746be4019bba557e29a7ba83d54c5

Regards,
Salvatore



More information about the Pkg-javascript-devel mailing list