Skip to content

Moment Regex vulnerability Issue #6725

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
finzero opened this issue Jan 23, 2025 · 1 comment
Open

Moment Regex vulnerability Issue #6725

finzero opened this issue Jan 23, 2025 · 1 comment

Comments

@finzero
Copy link

finzero commented Jan 23, 2025

I'm using ZAP to pentest my application, after the scan there's a found a vulnerability in a regex expression (similar to issue moment/moment#4163)

Image

Versions of ngx-bootstrap, Angular, and Bootstrap:
ngx-bootstrap: ^19.0.2
Angular:17.2.2
Bootstrap: ^4.5.3

is there any solution for this ?

@robinlieson92
Copy link

robinlieson92 commented Apr 29, 2025

I'm experiencing the same issue, can the admin here (@lexasq) help to update the moment dependency to version 2.30.1 so that there are no vulnerable issues?

Image

Versions of ngx-bootstrap, Angular, and Bootstrap:
ngx-bootstrap: ^19.0.2
Angular:19.2.9
Bootstrap: ^5.3.3

Find on this :
https://github.com/valor-software/ngx-bootstrap/blob/7d87cb4edb8981feb1bd8ccf5d25aa0ea7479b72/src/chronos/parse/regex.ts#L26C14-L26C24

same issue with moment.js vulnerable DDoS

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants