Vulnerabilities/

Outdated Static Dependency in vue-moment

Severity:
Medium

Description

Versions of vue-moment prior to 4.1.0 contain an Outdated Static Dependency. The package depends on moment and has it loaded statically instead of as a dependency that can be updated. It has [email protected] that contains a Regular Expression Denial of Service vulnerability.

Recommendation

Update the vue-moment package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vue-moment
Anything's wrong? Let us know Last updated on January 09, 2023