This repository has been archived by the owner on Apr 8, 2024. It is now read-only.
CVE-2022-25881 (High) detected in http-cache-semantics-3.8.1.tgz #257
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-25881 - High Severity Vulnerability
Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies
Library home page: https://registry.npmjs.org/http-cache-semantics/-/http-cache-semantics-3.8.1.tgz
Path to dependency file: /generic-oauth/package.json
Path to vulnerable library: /tmp/git/generic-oauth/node_modules/npm/node_modules/http-cache-semantics/package.json
Dependency Hierarchy:
Found in base branch: master
This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.
Publish Date: 2023-01-31
URL: CVE-2022-25881
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-rc47-6667-2j5j
Release Date: 2023-01-31
Fix Resolution (http-cache-semantics): 4.1.1
Direct dependency fix Resolution (semantic-release): 17.0.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: