{"id":"GHSA-hrpp-f84w-xhfg","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hrpp-f84w-xhfg","summary":"Outdated Static Dependency in vue-moment","details":"Versions of `vue-moment` prior to 4.1.0 contain an Outdated Static Dependency. The package depends on `moment` and has it loaded statically instead of as a dependency that can be updated. It has `moment@2.19.1` that contains a Regular Expression Denial of Service vulnerability.\n\n\n## Recommendation\n\nUpgrade to version 4.1.0 or later.","published":"2020-09-04T16:55:06Z","modified":"2021-10-04T19:13:23Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"vue-moment","fixedVersion":"4.1.0"}],"fix":{"url":"https://github.com/brockpetrie/vue-moment/commit/a265e54660a7181a6795a12a97cebac5b305746e","label":"brockpetrie/vue-moment@a265e54"},"references":[{"type":"WEB","url":"https://github.com/brockpetrie/vue-moment/commit/a265e54660a7181a6795a12a97cebac5b305746e"},{"type":"PACKAGE","url":"https://github.com/brockpetrie/vue-moment"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-VUEMOMENT-538934"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1425"},{"type":"WEB","url":"https://www.npmjs.com/advisories/532"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-10-04T19:13:23Z"}}