Version 2.30.1

moment

Parse, validate, manipulate, and display dates in javascript.

Install Instructions

npm install moment
Current Version Release Date December 27, 2023
Package URL (purl) pkg:npm/moment@2.30.1

Find moment vulnerabilities in your supply chain.

Scan for Free

moment Vulnerabilities

Sort by
icon CVE (Latest)
  • icon CVE (Latest)
  • icon CVE (Oldest)
  • icon CVSS Score (Highest)
  • icon CVSS Score (Lowest)
CVE question mark icon CVSS Score question mark icon CWE(s) question mark icon EPSS Score question mark icon EPSS % question mark icon Impacted Versions
CVE-2022-24785 High 7.5 CWE-22, CWE-27 0.00387 0.73962
  • 2.0.0–2.29.1
  • 1.0.0–1.7.2
CVE-2022-31129 High 7.5 CWE-1333, CWE-400 0.0076 0.81755
  • 2.18.0–2.29.3
CVE-2017-18214 High 7.5 CWE-400 0.00238 0.6262
  • 2.0.0–2.19.2
  • 1.0.0–1.7.2
CVE-2016-4055 Medium 6.5 CWE-399, CWE-400 0.00809 0.82394
  • 2.0.0–2.11.1
  • 1.0.0–1.7.2

moment Vulnerability Remediation Guidance

CVE Description Full list of Impacted Versions Fix
CVE-2022-31129 moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried by default) has quadratic (N^2) complexity on specific inputs. Users may notice a noticeable slowdown is observed with inputs above 10k characters. Users who pass user-provided strings without sanity length checks to moment constructor are vulnerable to (Re)DoS attacks. The problem is patched in 2.29.4, the patch can be applied to all affected versions with minimal tweaking. Users are advised to upgrade. Users unable to upgrade should consider limiting date lengths accepted from user input. 2.29.1, 2.29.3, 2.29.2, 2.28.0, 2.25.3, 2.24.0, 2.22.2, 2.19.2 (Show all) Patch → 2.29.4
CVE-2022-24785 Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js. 2.29.1, 2.28.0, 2.25.3, 2.24.0, 2.22.2, 2.19.2, 2.19.1, 2.21.0 (Show all) Patch → 2.29.4
CVE-2017-18214 The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055. 2.19.2, 2.19.1, 2.18.1, 2.18.0, 2.17.1, 2.15.1, 2.12.0, 2.11.2 (Show all) Minor → 2.29.4
CVE-2016-4055 The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)." 2.11.1, 2.9.0, 2.10.3, 2.8.4, 2.8.1, 2.7.0, 2.5.1, 2.4.0 (Show all) Minor → 2.29.4

Instantly see if these moment vulnerabilities affect your code.

Scan for Free