CVE-2022-31129

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried by default) has quadratic (N^2) complexity on specific inputs. Users may notice a noticeable slowdown is observed with inputs above 10k characters. Users who pass user-provided strings without sanity length checks to moment constructor are vulnerable to (Re)DoS attacks. The problem is patched in 2.29.4, the patch can be applied to all affected versions with minimal tweaking. Users are advised to upgrade. Users unable to upgrade should consider limiting date lengths accepted from user input.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:momentjs:moment:*:*:*:*:*:node.js:*:*
cpe:2.3:a:momentjs:moment:*:*:*:*:*:nuget:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

07 Nov 2023, 03:47

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5/', 'name': 'FEDORA-2022-35b698150c', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q/', 'name': 'FEDORA-2022-85aa8e5706', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO/', 'name': 'FEDORA-2022-798fd95813', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O/', 'name': 'FEDORA-2022-b9ef7c3c3c', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q/ -

24 Jul 2023, 13:16

Type Values Removed Values Added
CWE CWE-400 CWE-1333

23 Feb 2023, 16:39

Type Values Removed Values Added
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
References (MLIST) https://lists.debian.org/debian-lts-announce/2023/01/msg00035.html - (MLIST) https://lists.debian.org/debian-lts-announce/2023/01/msg00035.html - Mailing List, Third Party Advisory
First Time Debian
Debian debian Linux

31 Jan 2023, 01:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/01/msg00035.html -

27 Oct 2022, 14:39

Type Values Removed Values Added
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q/ - Mailing List, Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O/ - Mailing List, Third Party Advisory
References (CONFIRM) https://security.netapp.com/advisory/ntap-20221014-0003/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20221014-0003/ - Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5/ - Mailing List, Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO/ - Mailing List, Third Party Advisory
CPE cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
First Time Fedoraproject
Fedoraproject fedora

14 Oct 2022, 13:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20221014-0003/ -

12 Sep 2022, 21:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO/ -

05 Sep 2022, 01:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O/ -

23 Jul 2022, 04:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5/ -
CWE NVD-CWE-Other CWE-400

14 Jul 2022, 14:34

Type Values Removed Values Added
References (MISC) https://huntr.dev/bounties/f0952b67-f2ff-44a9-a9cd-99e0a87cb633/ - (MISC) https://huntr.dev/bounties/f0952b67-f2ff-44a9-a9cd-99e0a87cb633/ - Exploit, Issue Tracking, Patch, Third Party Advisory
References (CONFIRM) https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g - (CONFIRM) https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g - Issue Tracking, Third Party Advisory
References (MISC) https://github.com/moment/moment/pull/6015#issuecomment-1152961973 - (MISC) https://github.com/moment/moment/pull/6015#issuecomment-1152961973 - Exploit, Issue Tracking, Patch, Third Party Advisory
References (MISC) https://github.com/moment/moment/commit/9a3b5894f3d5d602948ac8a02e4ee528a49ca3a3 - (MISC) https://github.com/moment/moment/commit/9a3b5894f3d5d602948ac8a02e4ee528a49ca3a3 - Patch, Third Party Advisory
CPE cpe:2.3:a:momentjs:moment:*:*:*:*:*:nuget:*:*
cpe:2.3:a:momentjs:moment:*:*:*:*:*:node.js:*:*
CWE CWE-400 NVD-CWE-Other
First Time Momentjs moment
Momentjs
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

08 Jul 2022, 09:15

Type Values Removed Values Added
References
  • (MISC) https://huntr.dev/bounties/f0952b67-f2ff-44a9-a9cd-99e0a87cb633/ -

06 Jul 2022, 18:58

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-06 18:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-31129

Mitre link : CVE-2022-31129

CVE.ORG link : CVE-2022-31129


JSON object : View

Products Affected

fedoraproject

  • fedora

debian

  • debian_linux

momentjs

  • moment
CWE
CWE-1333 CWE-400

Uncontrolled Resource Consumption