geonetwork / geonetwork/core-geonetwork

Severe ReDoS vulnerabilty: moment.js

Open
#3,387 7 comments 0 reactions 1 assignee Claimed by @fxprunayre View on GitHub
stale
Dominant language
Java
Stars
521
Forks
514
Avg merge
6d 13h
Merged PRs (30d)
19

Description

We have been informed of a severe regular expression Denial of Service (ReDoS) vulnerabilty caused by the use of an outdated version of moment.js by GeoNetwork:
* Description: This vulnerability was identified because the detected version of Moment.js, 2.2.1, is less than 2.11.2
* Path: /geonetwork/static/lib.js
* Fix: Upgrade to version 2.22.2 or later of Moment.js.
* References:
* http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
* https://nodesecurity.io/advisories/55

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.