VDB
Sign up
HIGH7.5

GHSA-446m-mv8f-q348

Regular Expression Denial of Service in moment

Quick fix

GHSA-446m-mv8f-q348 — moment: upgrade to the fixed version with the command below.

npm install moment@2.19.3

Details

Affected versions of `moment` are vulnerable to a low severity regular expression denial of service when parsing dates as strings.

## Recommendation

Update to version 2.19.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/moment
Introduced in: 0Fixed in: 2.19.3
Fixnpm install moment@2.19.3

References