Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in moment.js #543

Open
lakewebworks opened this issue Apr 5, 2024 · 0 comments
Open

Vulnerability in moment.js #543

lakewebworks opened this issue Apr 5, 2024 · 0 comments

Comments

@lakewebworks
Copy link

Hello, we're using Event Organiser on https://californiaopioidresponse.org and are very happy with it. However, it's government funded, and the site was just scanned by a third-party agency that has flagged a security vulnerability in the moment.js script, which I see was identified on GitHub back in April of 2022 (GHSA-8hfj-j24r-96c4).

It looks like it’s the version in use in Event Organiser is at version 2.9, the current version is 2.30.1, and the issue was patched in version 2.29.2.

Would it be possible to get moment.js updated to > 2.29.2 with the next plugin update? When might that be (we're being asked for timelines to remedy these detected vulnerabilities).

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant