Description
Versions of vue-moment prior to 4.1.0 contain an Outdated Static Dependency. The package depends on moment and has it loaded statically instead of as a dependency that can be updated. It has [email protected] that contains a Regular Expression Denial of Service vulnerability.
Recommendation
Update the vue-moment package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.1.0
- Patched version(s): 4.1.0
References
Could your website be exposed too?
SmartScanner can check your website for Outdated Static Dependency in vue-moment and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Malicious Package in vue-backbone - Vulnerability
- ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function - CVE-2024-9506
- Cross-Site Scripting in bootstrap-vue - Vulnerability
- Cross-Site Scripting in nextcloud-vue-collections - Vulnerability


