Title: [SECURITY VULNERABILITY] moment dependency
Last modified: March 5, 2018

---

# [SECURITY VULNERABILITY] moment dependency

 *  [forboding-angel](https://wordpress.org/support/users/forboding-angel/)
 * (@forboding-angel)
 * [8 years, 5 months ago](https://wordpress.org/support/topic/security-vulnerability-moment-dependency/)
 * We found a potential security vulnerability in one of your dependencies.
    The
   moment dependency defined in package-lock.json has a known moderate severity 
   security vulnerability in version range < 2.19.3 and should be updated.
 * These dependencies have been defined in the manifest files, such as /backupwordpress/
   package-lock.json
 * [https://nvd.nist.gov/vuln/detail/CVE-2017-18214](https://nvd.nist.gov/vuln/detail/CVE-2017-18214)
 * **CVE-2017-18214 Detail**
 * Description
    The moment module before 2.19.3 for Node.js is prone to a regular
   expression denial of service via a crafted date string, a different vulnerability
   than CVE-2016-4055.

Viewing 5 replies - 1 through 5 (of 5 total)

 *  Thread Starter [forboding-angel](https://wordpress.org/support/users/forboding-angel/)
 * (@forboding-angel)
 * [8 years, 5 months ago](https://wordpress.org/support/topic/security-vulnerability-moment-dependency/#post-10042126)
 * Forgot to mention that this was an aut-find thanks to github
 *  Plugin Contributor [Katrina “Kat” Moody](https://wordpress.org/support/users/katmoody/)
 * (@katmoody)
 * [8 years, 5 months ago](https://wordpress.org/support/topic/security-vulnerability-moment-dependency/#post-10042665)
 * Thanks for the head’s up – I’m pushing this through to our developers!
    Kat
 *  Plugin Contributor [Katrina “Kat” Moody](https://wordpress.org/support/users/katmoody/)
 * (@katmoody)
 * [8 years, 5 months ago](https://wordpress.org/support/topic/security-vulnerability-moment-dependency/#post-10057359)
 * Just a heads’ up should anyone else run into this one – We will be packaging 
   an update to these outdated libraries with a new update within the next week 
   or two and that should address this potential security issue. Should anyone have
   further questions on this please feel free to respond here and we will reply 
   as soon as we can!
 * Kat
 *  Thread Starter [forboding-angel](https://wordpress.org/support/users/forboding-angel/)
 * (@forboding-angel)
 * [8 years, 4 months ago](https://wordpress.org/support/topic/security-vulnerability-moment-dependency/#post-10147770)
 * You never released an update. It’s been a month.
 *  [David Anderson / Team Updraft](https://wordpress.org/support/users/davidanderson/)
 * (@davidanderson)
 * [8 years, 1 month ago](https://wordpress.org/support/topic/security-vulnerability-moment-dependency/#post-10466410)
 * > The moment module before 2.19.3 for Node.js
 * N.B. A browser environment is *not* Node.js.

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘[SECURITY VULNERABILITY] moment dependency’ is closed to new replies.

 * ![](https://ps.w.org/backupwordpress/assets/icon-256x256.jpg?rev=1105225)
 * [BackUpWordPress](https://wordpress.org/plugins/backupwordpress/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/backupwordpress/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/backupwordpress/)
 * [Active Topics](https://wordpress.org/support/plugin/backupwordpress/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/backupwordpress/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/backupwordpress/reviews/)

 * 5 replies
 * 3 participants
 * Last reply from: [David Anderson / Team Updraft](https://wordpress.org/support/users/davidanderson/)
 * Last activity: [8 years, 1 month ago](https://wordpress.org/support/topic/security-vulnerability-moment-dependency/#post-10466410)
 * Status: not resolved