GHSA-4p3w-j4w9-5jqw: Path Traversal
Impact
moment before 2.31.0 is vulnerable to path traversal in moment.locale(). When an application passes a non-string, attacker-influenced value to moment.locale(), a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the validation added in 2.29.2 for CVE-2022-24785.
This affects server-side (npm) users only. Plain string input is not affected: the existing validation correctly rejects strings that contain path separators.
Patches
This issue is patched in moment 2.31.0.
Workarounds
Validate that any user-supplied input is a string before passing it to moment.locale().
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/momentto a version that resolves this vulnerability.Fixed in 2.31.0 - Upgrade
Upgrade
momentto a version that resolves this vulnerability.Fixed in 2.31.0 - Compensating control
Validate that any user-supplied input is a string before passing it to moment.locale().
Event History
Frequently Asked Questions
Which deployments are affected?
Only server-side users of the npm package are affected. The issue applies to moment versions earlier than 2.31.0 when attacker-influenced values can reach moment.locale().
What input is required to exploit this issue?
An attacker must be able to supply a non-string value to moment.locale(). Plain string input is not affected because locale names containing path separators are rejected by the existing validation.
What can be done if upgrading is not immediately possible?
Validate that all user-supplied input is a string before passing it to moment.locale(). This prevents the crafted-object validation bypass described in the advisory.
How can I determine whether my application is exposed?
Review server-side code paths that call moment.locale() and determine whether they can receive attacker-influenced non-string values, such as objects. Applications that pass only validated strings to this function are not affected by this bypass.