CVE-2022-24785: Path Traversal in Moment.js
Impact This vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg fr is directly used to switch moment locale.
Patches This problem is patched in 2.29.2, and the patch can be applied to all affected versions (from 1.0.1 up until 2.29.1, inclusive).
Workarounds Sanitize user-provided locale name before passing it to moment.js.
References Are there any links users can visit to find out more?
For more information If you have any questions or comments about this advisory: Open an issue in moment repo
Other sources
A path traversal vulnerability was found in Moment.js that impacts npm (server) users. This issue occurs if a user-provided locale string is directly used to switch moment locale, which an attacker can exploit to change the correct path to one of their choice. This can result in a loss of integrity.
Moment.js could allow a remote attacker to traverse directories on the system, caused by improper validation of user supplied input. An attacker could send a specially-crafted locale string containing "dot dot" sequences (/../) to switch arbitrary moment locale.
— IBM
Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/servicemesh-prometheusto a version that resolves this vulnerability.Fixed in 0:2.14.0-18.el8.1 - Upgrade
Upgrade
redhat/servicemesh-prometheusto a version that resolves this vulnerability.Fixed in 0:2.23.0-9.el8 - Upgrade
Upgrade
redhat/cephto a version that resolves this vulnerability.Fixed in 2:16.2.10-94.el8c - Upgrade
Upgrade
redhat/eap7-hal-consoleto a version that resolves this vulnerability.Fixed in 0:3.3.12-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-hal-consoleto a version that resolves this vulnerability.Fixed in 0:3.3.12-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.6-1.redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.6-1.redhat_00001.1.el8 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.6-1.redhat_00001.1.el9 - Upgrade
Upgrade
nuget/Moment.jsto a version that resolves this vulnerability.Fixed in 2.29.2 - Upgrade
Upgrade
npm/momentto a version that resolves this vulnerability.Fixed in 2.29.2 - Upgrade
Upgrade
debian/node-momentto a version that resolves this vulnerability.Fixed in 2.29.1+ds-2+deb11u2Fixed in 2.29.4+ds-1 - Upgrade
Upgrade
redhat/moment vto a version that resolves this vulnerability.Fixed in 2.29.2 - Upgrade
Upgrade
momentto a version that resolves this vulnerability.Fixed in 2.29.2 - Compensating control
Sanitize the user-provided locale name before passing it to Moment.js when switching moment locale (e.g., do not directly use attacker-controlled locale strings like `fr` to set the locale).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-24785?
CVE-2022-24785 is a path traversal vulnerability in Moment.js that impacts npm (server) users.
How does the path traversal vulnerability in Moment.js impact users?
The path traversal vulnerability in Moment.js impacts npm (server) users, especially if a user-provided locale string is directly used to switch moment locale.
What versions of Moment.js are affected by CVE-2022-24785?
Versions 1.0.1 to 2.29.1 of Moment.js are affected by CVE-2022-24785.
What is the severity of CVE-2022-24785?
CVE-2022-24785 has a severity level of high (7).
How can I fix the path traversal vulnerability in Moment.js?
To fix the path traversal vulnerability in Moment.js, update to version 2.29.2.