Moment.js Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2022-24785 - Vulnerability Database

Moment.js Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2022-24785

High
Reference: CVE-2022-24785
Title: Moment.js Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

Moment.js is a JavaScript date library for parsing validating manipulating and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1 especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2 and the patch can be applied to all affected versions. As a workaround sanitize the user-provided locale name before passing it to Moment.js.