GHSA-hrpp-f84w-xhfg
MODERATEVersions of vue-moment prior to 4.1.0 contain an Outdated Static Dependency. The package depends on moment and has it loaded statically instead of as a dependency that can be updated. It has moment@2.19.1 that contains a Regular Expression Denial of Service vulnerability.
- Affected
- < 4.1.0
- Fixed in
- 4.1.0
- Published
- 2020-09-04
- Source
- github