CVE-2022-31129

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried by default) has quadratic (N^2) complexity on specific inputs. Users may notice a noticeable slowdown is observed with inputs above 10k characters. Users who pass user-provided strings without sanity length checks to moment constructor are vulnerable to (Re)DoS attacks. The problem is patched in 2.29.4, the patch can be applied to all affected versions with minimal tweaking. Users are advised to upgrade. Users unable to upgrade should consider limiting date lengths accepted from user input.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:momentjs:moment:*:*:*:*:*:node.js:*:*
cpe:2.3:a:momentjs:moment:*:*:*:*:*:nuget:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

24 Jul 2023, 13:16

Type Values Removed Values Added
CWE CWE-400 CWE-1333

23 Feb 2023, 16:39

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/01/msg00035.html - Mailing List, Third Party Advisory

27 Oct 2022, 14:39

Type Values Removed Values Added
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q/ - Mailing List, Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO/ - Mailing List, Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5/ - Mailing List, Third Party Advisory
References (CONFIRM) https://security.netapp.com/advisory/ntap-20221014-0003/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20221014-0003/ - Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O/ - Mailing List, Third Party Advisory
CPE cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

14 Oct 2022, 13:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20221014-0003/ -

12 Sep 2022, 21:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO/ -

05 Sep 2022, 01:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O/ -

23 Jul 2022, 04:15

Type Values Removed Values Added
CWE NVD-CWE-Other CWE-400
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q/ -

14 Jul 2022, 14:34

Type Values Removed Values Added
CPE cpe:2.3:a:momentjs:moment:*:*:*:*:*:nuget:*:*
cpe:2.3:a:momentjs:moment:*:*:*:*:*:node.js:*:*
References (CONFIRM) https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g - (CONFIRM) https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g - Issue Tracking, Third Party Advisory
References (MISC) https://github.com/moment/moment/commit/9a3b5894f3d5d602948ac8a02e4ee528a49ca3a3 - (MISC) https://github.com/moment/moment/commit/9a3b5894f3d5d602948ac8a02e4ee528a49ca3a3 - Patch, Third Party Advisory
References (MISC) https://github.com/moment/moment/pull/6015#issuecomment-1152961973 - (MISC) https://github.com/moment/moment/pull/6015#issuecomment-1152961973 - Exploit, Issue Tracking, Patch, Third Party Advisory
References (MISC) https://huntr.dev/bounties/f0952b67-f2ff-44a9-a9cd-99e0a87cb633/ - (MISC) https://huntr.dev/bounties/f0952b67-f2ff-44a9-a9cd-99e0a87cb633/ - Exploit, Issue Tracking, Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-400 NVD-CWE-Other

08 Jul 2022, 09:15

Type Values Removed Values Added
References
  • (MISC) https://huntr.dev/bounties/f0952b67-f2ff-44a9-a9cd-99e0a87cb633/ -

06 Jul 2022, 18:58

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-06 18:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-31129

Mitre link : CVE-2022-31129

CVE.ORG link : CVE-2022-31129


JSON object : View

Products Affected

momentjs

  • moment

fedoraproject

  • fedora

debian

  • debian_linux
CWE
CWE-1333

Inefficient Regular Expression Complexity

CWE-400

Uncontrolled Resource Consumption