Description
Versions of vue-moment prior to 4.1.0 contain an Outdated Static Dependency. The package depends on moment and has it loaded statically instead of as a dependency that can be updated. It has [email protected] that contains a Regular Expression Denial of Service vulnerability.
Recommendation
Update the vue-moment package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.1.0
- Patched version(s): 4.1.0
References
Related Issues
- Malicious Package in vue-backbone - Vulnerability
- ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function - CVE-2024-9506
- Cross-Site Scripting in bootstrap-vue - Vulnerability
- Cross-Site Scripting in nextcloud-vue-collections - Vulnerability
You might also like:
- Tags:
- npm
- vue-moment
Anything's wrong? Let us know Last updated on January 09, 2023


