This repository has been archived by the owner on Jul 13, 2021. It is now read-only.
WS-2019-0217 (Medium) detected in constantinople-3.0.2.tgz #71
Labels
security vulnerability
Security vulnerability detected by WhiteSource
WS-2019-0217 - Medium Severity Vulnerability
Vulnerable Library - constantinople-3.0.2.tgz
Determine whether a JavaScript expression evaluates to a constant (using UglifyJS)
Library home page: https://registry.npmjs.org/constantinople/-/constantinople-3.0.2.tgz
Path to dependency file: curratelo/package.json
Path to vulnerable library: curratelo/node_modules/constantinople/package.json
Dependency Hierarchy:
Found in HEAD commit: 9d25ffce923d8b5ee8e4d3a66723fb5744328814
Vulnerability Details
constantinople before 3.1.1 affected by a sandbox bypass.
Publish Date: 2018-02-09
URL: WS-2019-0217
CVSS 2 Score Details (5.0)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/568
Release Date: 2019-09-05
Fix Resolution: 3.1.1
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: