Momentjs Moment 1.0.1 for Nuget

CPE Details

Momentjs Moment 1.0.1 for Nuget
1.0.1
2022-04-11
15h24 +00:00
2022-06-22
11h55 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:momentjs:moment:1.0.1:*:*:*:*:nuget:*:*

Informations

Vendor

momentjs

Product

moment

Version

1.0.1

Target Software

nuget

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-24785 2022-04-04 00h00 +00:00 Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.
7.5
High