This repository has been archived by the owner on Apr 8, 2024. It is now read-only.
CVE-2022-25883 (High) detected in multiple libraries #261
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-25883 - High Severity Vulnerability
semver-5.3.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.3.0.tgz
Path to dependency file: /generic-oauth/package.json
Path to vulnerable library: /tmp/git/generic-oauth/node_modules/npm/node_modules/node-gyp/node_modules/semver/package.json
Dependency Hierarchy:
semver-5.6.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.6.0.tgz
Path to dependency file: /generic-oauth/package.json
Path to vulnerable library: /tmp/git/generic-oauth/node_modules/npm/node_modules/semver/package.json
Dependency Hierarchy:
semver-5.7.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.7.0.tgz
Path to dependency file: /generic-oauth/package.json
Path to vulnerable library: /tmp/git/generic-oauth/node_modules/gcs-resumable-upload/node_modules/semver/package.json
Dependency Hierarchy:
Found in base branch: master
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
Publish Date: 2023-06-21
URL: CVE-2022-25883
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-c2qf-rxjj-qqgw
Release Date: 2023-06-21
Fix Resolution (semver): 5.7.2
Direct dependency fix Resolution (semantic-release): 22.0.0
Fix Resolution (semver): 5.7.2
Direct dependency fix Resolution (semantic-release): 22.0.0
Fix Resolution (semver): 5.7.2
Direct dependency fix Resolution (jest): 27.0.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: