{"id":"GHSA-v78c-4p63-2j6c","aliases":[],"url":"https://o3.security/vulnerability/GHSA-v78c-4p63-2j6c","summary":"Cleartext Transmission of Sensitive Information in moment-timezone","details":"### Impact\n\n* if Alice uses `grunt data` (or `grunt release`) to prepare a custom-build, moment-timezone with the latest tzdata from IANA's website\n* and Mallory intercepts the request to IANA's unencrypted ftp server, Mallory can serve data which might exploit further stages of the moment-timezone tzdata pipeline, or potentially produce a tainted version of moment-timezone (practicality of such attacks is not proved)\n\n### Patches\nProblem has been patched in version 0.5.35, patch should be applicable with minor modifications to all affected versions. The patch includes changing the FTP endpoint with an HTTPS endpoint.\n\n### Workarounds\nSpecify the exact version of tzdata (like `2014d`, full command being `grunt data:2014d`, then run the rest of the release tasks by hand), or just apply the patch before issuing the grunt command.\n","published":"2022-08-30T20:28:43Z","modified":"2022-08-30T20:28:43Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"moment-timezone","fixedVersion":"0.5.35"}],"fix":{"url":"https://github.com/moment/moment-timezone/commit/7915ac567ab19700e44ad6b5d8ef0b85e48a9e75","label":"moment/moment-timezone@7915ac5"},"references":[{"type":"WEB","url":"https://github.com/moment/moment-timezone/security/advisories/GHSA-v78c-4p63-2j6c"},{"type":"WEB","url":"https://github.com/moment/moment-timezone/commit/7915ac567ab19700e44ad6b5d8ef0b85e48a9e75"},{"type":"PACKAGE","url":"https://github.com/moment/moment-timezone"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-08-30T20:28:43Z"}}