Skip to content
This repository has been archived by the owner on Apr 8, 2024. It is now read-only.

CVE-2022-37598 (Critical) detected in uglify-js-3.6.0.tgz #245

Open
mend-bolt-for-github bot opened this issue Oct 23, 2022 · 0 comments
Open

CVE-2022-37598 (Critical) detected in uglify-js-3.6.0.tgz #245

mend-bolt-for-github bot opened this issue Oct 23, 2022 · 0 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-bolt-for-github
Copy link
Contributor

mend-bolt-for-github bot commented Oct 23, 2022

CVE-2022-37598 - Critical Severity Vulnerability

Vulnerable Library - uglify-js-3.6.0.tgz

JavaScript parser, mangler/compressor and beautifier toolkit

Library home page: https://registry.npmjs.org/uglify-js/-/uglify-js-3.6.0.tgz

Path to dependency file: /generic-oauth/package.json

Path to vulnerable library: /tmp/git/generic-oauth/node_modules/uglify-js/package.json

Dependency Hierarchy:

  • semantic-release-15.13.14.tgz (Root Library)
    • release-notes-generator-7.1.4.tgz
      • conventional-changelog-writer-4.0.3.tgz
        • handlebars-4.1.2.tgz
          • uglify-js-3.6.0.tgz (Vulnerable Library)

Found in base branch: master

Vulnerability Details

** DISPUTED ** Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.

Publish Date: 2022-10-20

URL: CVE-2022-37598

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2022-10-20

Fix Resolution (uglify-js): 3.13.10

Direct dependency fix Resolution (semantic-release): 15.13.15


Step up your Open Source Security Game with Mend here

@mend-bolt-for-github mend-bolt-for-github bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Oct 23, 2022
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2022-37598 (High) detected in uglify-js-3.6.0.tgz CVE-2022-37598 (Critical) detected in uglify-js-3.6.0.tgz Dec 12, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

0 participants