This repository has been archived by the owner on Apr 8, 2024. It is now read-only.
CVE-2022-33987 (Medium) detected in got-6.7.1.tgz #241
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-33987 - Medium Severity Vulnerability
Simplified HTTP requests
Library home page: https://registry.npmjs.org/got/-/got-6.7.1.tgz
Path to dependency file: /generic-oauth/package.json
Path to vulnerable library: /tmp/git/generic-oauth/node_modules/npm/node_modules/got/package.json
Dependency Hierarchy:
Found in base branch: master
The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
Publish Date: 2022-06-18
URL: CVE-2022-33987
Base Score Metrics:
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-33987
Release Date: 2022-06-18
Fix Resolution (got): 11.8.6
Direct dependency fix Resolution (semantic-release): 17.0.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: