This repository has been archived by the owner on Apr 8, 2024. It is now read-only.
CVE-2021-23440 (Critical) detected in set-value-0.4.3.tgz, set-value-2.0.0.tgz #243
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2021-23440 - Critical Severity Vulnerability
set-value-0.4.3.tgz
Create nested values and any intermediaries using dot notation (`'a.b.c'`) paths.
Library home page: https://registry.npmjs.org/set-value/-/set-value-0.4.3.tgz
Path to dependency file: /generic-oauth/package.json
Path to vulnerable library: /tmp/git/generic-oauth/node_modules/union-value/node_modules/set-value/package.json
Dependency Hierarchy:
set-value-2.0.0.tgz
Create nested values and any intermediaries using dot notation (`'a.b.c'`) paths.
Library home page: https://registry.npmjs.org/set-value/-/set-value-2.0.0.tgz
Path to dependency file: /generic-oauth/package.json
Path to vulnerable library: /tmp/git/generic-oauth/node_modules/set-value/package.json
Dependency Hierarchy:
Found in HEAD commit: fb424c23584c31665ca91d557b2fbd20eca56cc5
Found in base branch: master
Mend Note: After conducting further research, Mend has determined that all versions of set-value before versions 2.0.1, 4.0.1 are vulnerable to CVE-2021-23440.
Publish Date: 2021-09-12
URL: CVE-2021-23440
Base Score Metrics:
Type: Upgrade version
Origin: https://www.huntr.dev/bounties/2eae1159-01de-4f82-a177-7478a408c4a2/
Release Date: 2021-09-12
Fix Resolution (set-value): 2.0.1
Direct dependency fix Resolution (lint-staged): 8.2.1
Fix Resolution (set-value): 2.0.1
Direct dependency fix Resolution (lint-staged): 8.2.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: