Description
All versions of moment-timezone from 0.1.0 contain build tasks vulnerable to command injection.
Recommendation
Update the moment-timezone package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.1.0, < 0.5.35
- Patched version(s): 0.5.35
References
Related Issues
- Cleartext Transmission of Sensitive Information in moment-timezone - Vulnerability
- chromedriver Command Injection vulnerability - CVE-2023-26156
- json-logic-js Command Injection vulnerability - CVE-2021-4329
- Command Injection in soletta-dev-app - Vulnerability
You might also like:
- Tags:
- npm
- moment-timezone
Anything's wrong? Let us know Last updated on January 12, 2023


