HIGH7.5
GHSA-446m-mv8f-q348
Regular Expression Denial of Service in moment
Quick fix
GHSA-446m-mv8f-q348 — moment: upgrade to the fixed version with the command below.
npm install moment@2.19.3Details
Affected versions of `moment` are vulnerable to a low severity regular expression denial of service when parsing dates as strings.
## Recommendation
Update to version 2.19.3 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-18214[ADVISORY]
- https://github.com/moment/moment/issues/4163[WEB]
- https://github.com/moment/moment/pull/4326[WEB]
- https://github.com/moment/moment/commit/69ed9d44957fa6ab12b73d2ae29d286a857b80eb[WEB]
- https://github.com/advisories/GHSA-446m-mv8f-q348[ADVISORY]
- https://github.com/moment/moment[PACKAGE]
- https://www.npmjs.com/advisories/532[WEB]
- https://www.tenable.com/security/tns-2019-02[WEB]