Open dev-mend-for-github-com[bot] opened 11 months ago
:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
:information_source: This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.
Vulnerable Library - moment-with-locales-2.12.0.js
Parse, validate, manipulate, and display dates
Library home page: https://cdnjs.cloudflare.com/ajax/libs/moment.js/2.12.0/moment-with-locales.js
Path to vulnerable library: /tapestry-core/src/main/resources/META-INF/assets/tapestry5/moment-2.12.0.js
Found in HEAD commit: aca16acc45f5f50f6a393f385ecf1826969eef4f
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2017-18214
### Vulnerable Library - moment-with-locales-2.12.0.jsParse, validate, manipulate, and display dates
Library home page: https://cdnjs.cloudflare.com/ajax/libs/moment.js/2.12.0/moment-with-locales.js
Path to vulnerable library: /tapestry-core/src/main/resources/META-INF/assets/tapestry5/moment-2.12.0.js
Dependency Hierarchy: - :x: **moment-with-locales-2.12.0.js** (Vulnerable Library)
Found in HEAD commit: aca16acc45f5f50f6a393f385ecf1826969eef4f
Found in base branch: master
### Vulnerability DetailsThe moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
Publish Date: 2018-03-04
URL: CVE-2017-18214
### CVSS 4 Score Details (8.7)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: N/A - Impact Metrics: - Confidentiality Impact: N/A - Integrity Impact: N/A - Availability Impact: N/A
For more information on CVSS4 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://github.com/advisories/GHSA-446m-mv8f-q348
Release Date: 2018-03-04
Fix Resolution: moment - 2.19.3