Lucene search

K
atlassian458e633c07a6JRASERVER-76371
HistoryOct 11, 2023 - 3:26 p.m.

Upgrade moment library to 2.29.2+ as required for CVE-2022-24785 and CVE-2022-31129

2023-10-1115:26:01
458e633c07a6
jira.atlassian.com
98
moment.js upgrade
version 2.29.2
cve-2022-24785
cve-2022-31129
jira service management

EPSS

0.008

Percentile

81.4%

Hi,

Is it possible to upgrade the moment.js library to 2.29.2Β  on all Jira SM versions? (It seems fixed in for Jira SW as mentioned https://jira.atlassian.com/browse/JRASERVER-75017) In JSM it is still discovered as a vulnerability.