Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Severe ReDoS vulnerabilty: moment.js #3387

Open
bchartier opened this issue Dec 21, 2018 · 7 comments
Open

Severe ReDoS vulnerabilty: moment.js #3387

bchartier opened this issue Dec 21, 2018 · 7 comments
Assignees
Labels
stale stale issue flagged for closure.
Projects
Milestone

Comments

@bchartier
Copy link

We have been informed of a severe regular expression Denial of Service (ReDoS) vulnerabilty caused by the use of an outdated version of moment.js by GeoNetwork:

@fxprunayre
Copy link
Member

Thanks, for reporting, it looks like 3.4.x and master are both using moment 2.18.1 cf. https://github.com/geonetwork/core-geonetwork/blob/3.4.x/web-ui/src/main/resources/catalog/lib/moment+langs.min.js#L82. Which version are you using ?

@bchartier
Copy link
Author

Hum 3.2.2. Sorry.
So, this vulnerability has been fixed as I can see in your answer.
Sorry again for this outdated alert.

@fxprunayre fxprunayre added this to the 3.2.3 milestone Dec 21, 2018
@fxprunayre
Copy link
Member

You can safely cherry-pick the commit if you need it applied to 3.2.2 313c7e2#diff-56c156a44c44136483e50386ea7842aa

@bchartier
Copy link
Author

Thank you very much.

@bchartier
Copy link
Author

I closed this issue too quickly.
An other vulnerabilty (less severe) exists with versions of Moment less than 2.19.3:
see moment/moment#4163 and https://nodesecurity.io/advisories/532

Sorry, I should have noticed this at the same time.

@fxprunayre
Copy link
Member

Update done for 3.6.0.

@fxprunayre fxprunayre self-assigned this Jan 7, 2019
@fxprunayre fxprunayre added this to To do in 3.6.0 via automation Jan 7, 2019
@bchartier
Copy link
Author

Thank you

@fxprunayre fxprunayre moved this from To do to Done in 3.6.0 Jan 9, 2019
@ticheler ticheler added the stale stale issue flagged for closure. label Mar 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
stale stale issue flagged for closure.
Projects
No open projects
3.6.0
  
Done
Development

No branches or pull requests

3 participants