SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24785

A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale.

HIGH 7.5EPSS 5.52%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
5.52% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-22, CWE-27
Affected
momentjs/moment · tenable/tenable.sc · netapp/active iq · fedoraproject/fedora · debian/debian linux
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.