QID 981332
QID 981332: Nodejs (npm) Security Update for moment (GHSA-446m-mv8f-q348)
Affected versions of `moment` are vulnerable to a low severity regular expression denial of service when parsing dates as strings.
## Recommendation
Update to version 2.19.3 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-446m-mv8f-q348 for updates pertaining to this vulnerability.
Vendor References
- GHSA-446m-mv8f-q348 -
github.com/advisories/GHSA-446m-mv8f-q348
CVEs related to QID 981332
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-446m-mv8f-q348 | moment |
|