Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Moment in Pakage.json have 3 vulnerability have POC #136

Open
leetae9029 opened this issue Sep 23, 2024 · 0 comments
Open

Moment in Pakage.json have 3 vulnerability have POC #136

leetae9029 opened this issue Sep 23, 2024 · 0 comments

Comments

@leetae9029
Copy link

https://github.com/QingdaoU/OnlineJudgeFE/blob/master/package.json#L41

i see 3 vulnerability in here:

i test in my web site with url http://labs.codetoanbug.com:8000/static/js/vendor.dll.7d98bec.js

moment 2.22.2 in vendor.dll.7d98bec.js
CVE-2022-24785: This vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg fr is directly used to switch moment locale.

CVE-2022-31129, CVE-2023-22467: Regular Expression Denial of Service (ReDoS), Affecting moment package, versions >=2.18.0 <2.29.4

Vue 2.5.17 in vendor.dll.7d98bec.js
Bump vue-server-renderer's dependency of serialize-javascript to 2.1.2 https://github.com/vuejs/vue/releases/tag/v2.6.11

i testing POC in my local server i Redos impact slow my website

i building new version Online Juger

Contact Me: longbinhquoitay8@gmail.com
Thank for Read!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant