CVE-2022-24785
Vulnerability Summary
Timeline
Description
Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS Trends
Current EPSS score: 13.90%• Percentile: 96%
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
- CWE-27•Path Traversal: 'dir/../../filename'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize multiple internal "../" sequences that can resolve to a location that is outside of that directory.
Affected Systems
- chainguard•wazuh-dashboard-security-plugin
< 4.14.6-r5
- chainguard•wazuh-dashboard-security-plugin-fips
< 4.14.6-r2
- debian•node-moment
< 2.29.1+ds-2+deb11u1 | < 2.29.2+ds-1 | < 2.29.2+ds-1 | < 2.29.2+ds-1
- debian•debian_linux
10.0
- fedoraproject•fedora
35 | 36
- moment•moment
≥ 1.0.1, < 2.29.2
- momentjs•moment
≥ 1.0.1, < 2.29.2
- netapp•active_iq
na
- Npm•moment
< 2.29.2
- NuGet•Moment.js
< 2.29.2
- redhat•ceph
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-base
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-base-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-common
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-common-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-debugsource
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-fuse
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-fuse-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-grafana-dashboards
< 2:16.2.10-94.el8cp
- redhat•ceph-immutable-object-cache
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-immutable-object-cache-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-mds
< 2:16.2.10-94.el8cp
- redhat•ceph-mds-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-mgr
< 2:16.2.10-94.el8cp
- redhat•ceph-mgr-cephadm
< 2:16.2.10-94.el8cp
- redhat•ceph-mgr-dashboard
< 2:16.2.10-94.el8cp
- redhat•ceph-mgr-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-mgr-diskprediction-local
< 2:16.2.10-94.el8cp
- redhat•ceph-mgr-k8sevents
< 2:16.2.10-94.el8cp
- redhat•ceph-mgr-modules-core
< 2:16.2.10-94.el8cp
- redhat•ceph-mgr-rook
< 2:16.2.10-94.el8cp
- redhat•ceph-mib
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-mon
< 2:16.2.10-94.el8cp
- redhat•ceph-mon-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-osd
< 2:16.2.10-94.el8cp
- redhat•ceph-osd-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-prometheus-alerts
< 2:16.2.10-94.el8cp
- redhat•ceph-radosgw
< 2:16.2.10-94.el8cp
- redhat•ceph-radosgw-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-resource-agents
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-selinux
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•ceph-test
< 2:16.2.10-94.el8cp
- redhat•ceph-test-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•cephadm
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•cephfs-mirror
< 2:16.2.10-94.el8cp
- redhat•cephfs-mirror-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•cephfs-top
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•libcephfs-devel
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•libcephfs2
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
- redhat•libcephfs2-debuginfo
< 2:16.2.10-94.el8cp | < 2:16.2.10-94.el9cp
Showing first 50 affected entries in server-rendered view.
References (124)
- https://github.com/moment/moment/security/advisories/GHSA-8hfj-j24r-96c4
- https://github.com/moment/moment/commit/4211bfc8f15746be4019bba557e29a7ba83d54c5
- https://www.tenable.com/security/tns-2022-09
- https://security.netapp.com/advisory/ntap-20220513-0006/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5/
- https://lists.debian.org/debian-lts-announce/2023/01/msg00035.html
- https://security.netapp.com/advisory/ntap-20241108-0002/
- https://nvd.nist.gov/vuln/detail/CVE-2022-24785
- https://github.com/moment/moment
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5
- https://security.netapp.com/advisory/ntap-20220513-0006
- https://security.netapp.com/advisory/ntap-20241108-0002
- https://access.redhat.com/errata/RHSA-2023:0076
- https://access.redhat.com/security/updates/classification/#moderate
- https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/5.3/html/release_notes/index
- https://bugzilla.redhat.com/show_bug.cgi?id=1749627
- https://bugzilla.redhat.com/show_bug.cgi?id=1827519
- https://bugzilla.redhat.com/show_bug.cgi?id=1905785
- https://bugzilla.redhat.com/show_bug.cgi?id=1941668
- https://bugzilla.redhat.com/show_bug.cgi?id=1957088
- https://bugzilla.redhat.com/show_bug.cgi?id=1986826
- https://bugzilla.redhat.com/show_bug.cgi?id=1989527
- https://bugzilla.redhat.com/show_bug.cgi?id=2011686
- https://bugzilla.redhat.com/show_bug.cgi?id=2014330
- https://bugzilla.redhat.com/show_bug.cgi?id=2015028
- https://bugzilla.redhat.com/show_bug.cgi?id=2017660
- https://bugzilla.redhat.com/show_bug.cgi?id=2019870
- https://bugzilla.redhat.com/show_bug.cgi?id=2021009
- https://bugzilla.redhat.com/show_bug.cgi?id=2023164
- https://bugzilla.redhat.com/show_bug.cgi?id=2023552
- https://bugzilla.redhat.com/show_bug.cgi?id=2024308
- https://bugzilla.redhat.com/show_bug.cgi?id=2025932
- https://bugzilla.redhat.com/show_bug.cgi?id=2026101
- https://bugzilla.redhat.com/show_bug.cgi?id=2026282
- https://bugzilla.redhat.com/show_bug.cgi?id=2028220
- https://bugzilla.redhat.com/show_bug.cgi?id=2037041
- https://bugzilla.redhat.com/show_bug.cgi?id=2041692
- https://bugzilla.redhat.com/show_bug.cgi?id=2042394
- https://bugzilla.redhat.com/show_bug.cgi?id=2052516
- https://bugzilla.redhat.com/show_bug.cgi?id=2052916
- https://bugzilla.redhat.com/show_bug.cgi?id=2055137
- https://bugzilla.redhat.com/show_bug.cgi?id=2062794
- https://bugzilla.redhat.com/show_bug.cgi?id=2064481
- https://bugzilla.redhat.com/show_bug.cgi?id=2066453
- https://bugzilla.redhat.com/show_bug.cgi?id=2072009
- https://bugzilla.redhat.com/show_bug.cgi?id=2072510
- https://bugzilla.redhat.com/show_bug.cgi?id=2072690
- https://bugzilla.redhat.com/show_bug.cgi?id=2075214
- https://bugzilla.redhat.com/show_bug.cgi?id=2086441
- https://bugzilla.redhat.com/show_bug.cgi?id=2086471
- https://bugzilla.redhat.com/show_bug.cgi?id=2089220
- https://bugzilla.redhat.com/show_bug.cgi?id=2091773
- https://bugzilla.redhat.com/show_bug.cgi?id=2095062
- https://bugzilla.redhat.com/show_bug.cgi?id=2095670
- https://bugzilla.redhat.com/show_bug.cgi?id=2100553
- https://bugzilla.redhat.com/show_bug.cgi?id=2100602
- https://bugzilla.redhat.com/show_bug.cgi?id=2101807
- https://bugzilla.redhat.com/show_bug.cgi?id=2102934
- https://bugzilla.redhat.com/show_bug.cgi?id=2104835
- https://bugzilla.redhat.com/show_bug.cgi?id=2105251
- https://bugzilla.redhat.com/show_bug.cgi?id=2105309
- https://bugzilla.redhat.com/show_bug.cgi?id=2105324
- https://bugzilla.redhat.com/show_bug.cgi?id=2107405
- https://bugzilla.redhat.com/show_bug.cgi?id=2108394
- https://bugzilla.redhat.com/show_bug.cgi?id=2108707
- https://bugzilla.redhat.com/show_bug.cgi?id=2108886
- https://bugzilla.redhat.com/show_bug.cgi?id=2109256
- https://bugzilla.redhat.com/show_bug.cgi?id=2109675
- https://bugzilla.redhat.com/show_bug.cgi?id=2109886
- https://bugzilla.redhat.com/show_bug.cgi?id=2109935
- https://bugzilla.redhat.com/show_bug.cgi?id=2110008
- https://bugzilla.redhat.com/show_bug.cgi?id=2110338
- https://bugzilla.redhat.com/show_bug.cgi?id=2110865
- https://bugzilla.redhat.com/show_bug.cgi?id=2111488
- https://bugzilla.redhat.com/show_bug.cgi?id=2114607
- https://bugzilla.redhat.com/show_bug.cgi?id=2117313
- https://bugzilla.redhat.com/show_bug.cgi?id=2117672
- https://bugzilla.redhat.com/show_bug.cgi?id=2118295
- https://bugzilla.redhat.com/show_bug.cgi?id=2118798
- https://bugzilla.redhat.com/show_bug.cgi?id=2119256
- https://bugzilla.redhat.com/show_bug.cgi?id=2119449
- https://bugzilla.redhat.com/show_bug.cgi?id=2119774
- https://bugzilla.redhat.com/show_bug.cgi?id=2119853
- https://bugzilla.redhat.com/show_bug.cgi?id=2120187
- https://bugzilla.redhat.com/show_bug.cgi?id=2120262
- https://bugzilla.redhat.com/show_bug.cgi?id=2121462
- https://bugzilla.redhat.com/show_bug.cgi?id=2121489
- https://bugzilla.redhat.com/show_bug.cgi?id=2121548
- https://bugzilla.redhat.com/show_bug.cgi?id=2121673
- https://bugzilla.redhat.com/show_bug.cgi?id=2122130
- https://bugzilla.redhat.com/show_bug.cgi?id=2123335
- https://bugzilla.redhat.com/show_bug.cgi?id=2123423
- https://bugzilla.redhat.com/show_bug.cgi?id=2124423
- https://bugzilla.redhat.com/show_bug.cgi?id=2126787
- https://bugzilla.redhat.com/show_bug.cgi?id=2127319
- https://bugzilla.redhat.com/show_bug.cgi?id=2128194
- https://bugzilla.redhat.com/show_bug.cgi?id=2129718
- https://bugzilla.redhat.com/show_bug.cgi?id=2130116
- https://bugzilla.redhat.com/show_bug.cgi?id=2131932
- https://bugzilla.redhat.com/show_bug.cgi?id=2132481
- https://bugzilla.redhat.com/show_bug.cgi?id=2135334
- https://bugzilla.redhat.com/show_bug.cgi?id=2136551
- https://bugzilla.redhat.com/show_bug.cgi?id=2138791
- https://bugzilla.redhat.com/show_bug.cgi?id=2139258
- https://bugzilla.redhat.com/show_bug.cgi?id=2139422
- https://bugzilla.redhat.com/show_bug.cgi?id=2140569
- https://bugzilla.redhat.com/show_bug.cgi?id=2142141
- https://bugzilla.redhat.com/show_bug.cgi?id=2142174
- https://bugzilla.redhat.com/show_bug.cgi?id=2142674
- https://bugzilla.redhat.com/show_bug.cgi?id=2143336
- https://bugzilla.redhat.com/show_bug.cgi?id=2145022
- https://bugzilla.redhat.com/show_bug.cgi?id=2149653
- https://bugzilla.redhat.com/show_bug.cgi?id=2150968
- https://bugzilla.redhat.com/show_bug.cgi?id=2153781
- https://bugzilla.redhat.com/show_bug.cgi?id=2156705
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0076.json
- https://access.redhat.com/security/cve/CVE-2022-24785
- https://www.cve.org/CVERecord?id=CVE-2022-24785
- https://security-tracker.debian.org/tracker/CVE-2022-24785
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24785.json