Details
-
Bug
-
Status: Closed (View Workflow)
-
P3
-
Resolution: Won't Do
-
None
-
None
-
-
Firebird
-
Not a bug
Description
As long as https://github.com/folio-org/ui-inventory-es is not archived (UISEES-73) it needs to get security fixes.
Upgrading moment from 2.24.0 to >= 2.29.4 fixes these vulnerabilities:
- https://nvd.nist.gov/vuln/detail/CVE-2022-31129 Regular Expression Denial of Service (ReDoS)
- https://nvd.nist.gov/vuln/detail/CVE-2022-24785 Directory Traversal
TestRail: Results
Attachments
Issue Links
- relates to
-
UIIN-2257 Upgrade moment from 2.24.0 to >= 2.29.4 fixing vulns
-
- Closed
-
-
STRIPES-678 pin moment to v2.24 (v2.25 broke the internet)
-
- Closed
-
-
STRIPES-702 update to current moment release, v2.29
-
- Closed
-
-
UISEES-73 Archive https://github.com/folio-org/ui-inventory-es
-
- Open
-