Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Moment.js 2.29.4 #9176

Closed
Mockabear opened this issue Sep 5, 2022 · 1 comment
Closed

Moment.js 2.29.4 #9176

Mockabear opened this issue Sep 5, 2022 · 1 comment

Comments

@Mockabear
Copy link

Mockabear commented Sep 5, 2022

Describe the bug

There is a known vulnerability in Primefaces Elite 11.0.7:

primefaces-11.0.7.jar: moment.js (pkg:javascript/moment.js@2.29.3) : CVE-2022-31129

Reproducer

No response

Expected behavior

No response

PrimeFaces edition

Elite

PrimeFaces version

11.0.7

Theme

No response

JSF implementation

All

JSF version

2.3

Java version

13

Browser(s)

No response

@Mockabear Mockabear added ‼️ needs-triage Issue needs triaging 🐞 defect Bug...Something isn't working labels Sep 5, 2022
@melloware
Copy link
Member

Please follow this ticket: #8968 I marked it "elite" but its up to PrimeTek to backport to PF11 etc.

See: https://github.com/primefaces/primefaces#community--elite--pro

@melloware melloware added elite This issue is related to an Elite release and removed 🐞 defect Bug...Something isn't working ‼️ needs-triage Issue needs triaging labels Sep 5, 2022
@mertsincan mertsincan added 11.0.8 🔒 security Security related issue or enhancement enhancement Additional functionality to current component and removed elite This issue is related to an Elite release enhancement Additional functionality to current component 🔒 security Security related issue or enhancement 11.0.8 labels Sep 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants