Skip to content

moment.js version upgrade request #22

@lmhkkang

Description

@lmhkkang

Due to current version of moment library that is nested in this library
is causing security vunlerability.

Will that be possile to upgrade moment library version?

below is snyk security report


moment - Regular Expression Denial of Service (ReDoS)

Detailed paths
Introduced through: react-tempusdominus-bootstrap@1.12.0 › tempusdominus@5.16.0 › moment@2.24.0
Fix: No remediation path available.
Introduced through: react-tempusdominus-bootstrap@1.12.0 › tempusdominus-bootstrap@5.37.0 › moment@2.24.0
Fix: No remediation path available.
Security information
Factors contributing to the scoring:
Snyk: CVSS 7.5 - High Severity

NVD: CVSS 7.5 - High Severity
Why are the scores different? Learn how Snyk evaluates vulnerability scores
Overview
moment is a lightweight JavaScript date library for parsing, validating, manipulating, and formatting dates.

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the preprocessRFC2822() function in from-string.js, when processing a very long crafted string (over 10k characters).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions