stephenharris / Event-Organiser

WordPress plug-in, Event Organiser, development repository
http://wordpress.org/extend/plugins/event-organiser/
GNU General Public License v3.0
100 stars 76 forks source link

Vulnerability in moment.js #543

Open lakewebworks opened 5 months ago

lakewebworks commented 5 months ago

Hello, we're using Event Organiser on https://californiaopioidresponse.org and are very happy with it. However, it's government funded, and the site was just scanned by a third-party agency that has flagged a security vulnerability in the moment.js script, which I see was identified on GitHub back in April of 2022 (https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4).

It looks like it’s the version in use in Event Organiser is at version 2.9, the current version is 2.30.1, and the issue was patched in version 2.29.2.

Would it be possible to get moment.js updated to > 2.29.2 with the next plugin update? When might that be (we're being asked for timelines to remedy these detected vulnerabilities).

Thanks!