This repository has been archived by the owner on May 12, 2023. It is now read-only.
forked from pandao/editor.md
-
Notifications
You must be signed in to change notification settings - Fork 2
WS-2020-0120 (High) detected in node-static-0.7.11.tgz #11
Labels
security vulnerability
Security vulnerability detected by WhiteSource
Comments
mend-bolt-for-github
bot
added
the
security vulnerability
Security vulnerability detected by WhiteSource
label
Oct 21, 2021
mend-bolt-for-github
bot
changed the title
WS-2020-0120 (High) detected in node-static-0.6.0.tgz
WS-2020-0120 (High) detected in node-static-0.6.0.tgz - autoclosed
Dec 17, 2021
✔️ This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory. |
mend-bolt-for-github
bot
changed the title
WS-2020-0120 (High) detected in node-static-0.6.0.tgz - autoclosed
WS-2020-0120 (High) detected in node-static-0.6.0.tgz
Feb 3, 2022
ℹ️ This issue was automatically re-opened by WhiteSource because the vulnerable library in the specific branch(es) has been detected in the WhiteSource inventory. |
mend-bolt-for-github
bot
changed the title
WS-2020-0120 (High) detected in node-static-0.6.0.tgz
WS-2020-0120 (High) detected in node-static-0.6.0.tgz - autoclosed
Feb 4, 2022
✔️ This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory. |
mend-bolt-for-github
bot
changed the title
WS-2020-0120 (High) detected in node-static-0.6.0.tgz - autoclosed
WS-2020-0120 (High) detected in node-static-0.7.11.tgz
Feb 15, 2022
ℹ️ This issue was automatically re-opened by WhiteSource because the vulnerable library in the specific branch(es) has been detected in the WhiteSource inventory. |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
WS-2020-0120 - High Severity Vulnerability
Vulnerable Library - node-static-0.7.11.tgz
simple, compliant file streaming module for node
Library home page: https://registry.npmjs.org/node-static/-/node-static-0.7.11.tgz
Path to dependency file: /lib/codemirror/package.json
Path to vulnerable library: /lib/codemirror/node_modules/node-static/package.json
Dependency Hierarchy:
Found in HEAD commit: 3536c96518d940a17281ef2d14155d06cf61d37a
Found in base branch: master
Vulnerability Details
All versions of node-static are vulnerable to a Denial of Service due to missing validation of pathname string.
Publish Date: 2020-06-09
URL: WS-2020-0120
CVSS 3 Score Details (7.5)
Base Score Metrics:
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: