Skip to content

Vulnerability issues #35

@viniciusdc

Description

@viniciusdc

Greetings, recently we ran a security check (Trivy) in our installed Jupyter image (jupyterhub==1.5.0 )and spotted the following vulnerability issue, and looking over the discussion on #9 I thought it was worth mentioning those here:

CVE-2022-24785
High
Package: moment
Installed Version: 2.29.1
Vulnerability CVE-2022-24785
Severity: HIGH
Fixed Version: 2.29.2
Link: CVE-2022-24785

maybe relevant GHSA-8hfj-j24r-96c4
found in opt/conda/share/jupyterhub/static/components/moment/package.json:1
Thanks in advance.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions