Description
All versions of moment-timezone from 0.1.0 contain build tasks vulnerable to command injection.
Recommendation
Update the moment-timezone package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.1.0, < 0.5.35
- Patched version(s): 0.5.35
References
Could your website be exposed too?
SmartScanner can check your website for Command Injection in moment-timezone and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cleartext Transmission of Sensitive Information in moment-timezone - Vulnerability
- chromedriver Command Injection vulnerability - CVE-2023-26156
- json-logic-js Command Injection vulnerability - CVE-2021-4329
- Command Injection in soletta-dev-app - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated January 12, 2023


