-
Notifications
You must be signed in to change notification settings - Fork 2
Description
WS-2018-0232 - Medium Severity Vulnerability
Vulnerable Libraries - underscore.string-2.3.3.tgz, underscore.string-2.4.0.tgz, underscore.string-2.2.1.tgz
underscore.string-2.3.3.tgz
String manipulation extensions for Underscore.js javascript library.
Library home page: https://registry.npmjs.org/underscore.string/-/underscore.string-2.3.3.tgz
Path to dependency file: /justapis-javascript-sdk/package.json
Path to vulnerable library: justapis-javascript-sdk/node_modules/grunt-legacy-log-utils/node_modules/underscore.string/package.json
Dependency Hierarchy:
- grunt-0.4.5.tgz (Root Library)
- grunt-legacy-log-0.1.3.tgz
- ❌ underscore.string-2.3.3.tgz (Vulnerable Library)
- grunt-legacy-log-0.1.3.tgz
underscore.string-2.4.0.tgz
String manipulation extensions for Underscore.js javascript library.
Library home page: https://registry.npmjs.org/underscore.string/-/underscore.string-2.4.0.tgz
Path to dependency file: /justapis-javascript-sdk/package.json
Path to vulnerable library: justapis-javascript-sdk/node_modules/argparse/node_modules/underscore.string/package.json
Dependency Hierarchy:
- grunt-0.4.5.tgz (Root Library)
- js-yaml-2.0.5.tgz
- argparse-0.1.16.tgz
- ❌ underscore.string-2.4.0.tgz (Vulnerable Library)
- argparse-0.1.16.tgz
- js-yaml-2.0.5.tgz
underscore.string-2.2.1.tgz
String manipulation extensions for Underscore.js javascript library.
Library home page: https://registry.npmjs.org/underscore.string/-/underscore.string-2.2.1.tgz
Path to dependency file: /justapis-javascript-sdk/package.json
Path to vulnerable library: justapis-javascript-sdk/node_modules/underscore.string/package.json
Dependency Hierarchy:
- grunt-0.4.5.tgz (Root Library)
- ❌ underscore.string-2.2.1.tgz (Vulnerable Library)
Vulnerability Details
Underscore.string, before 3.3.5, is vulnerable to Regular Expression Denial of Service (ReDoS).
Publish Date: 2018-10-03
URL: WS-2018-0232
Suggested Fix
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/745
Release Date: 2018-12-30
Fix Resolution: 3.3.5