This repository has been archived by the owner on Feb 8, 2024. It is now read-only.
c3-0.7.20.tgz: 1 vulnerabilities (highest severity is: 7.5) #63
Labels
security vulnerability
Security vulnerability detected by WhiteSource
Vulnerable Library - c3-0.7.20.tgz
Path to dependency file: /manager/gui/package.json
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the section "Details" below to see if there is a version of transitive dependency where vulnerability is fixed.
Details
WS-2022-0322
Vulnerable Library - d3-color-1.4.1.tgz
Color spaces! RGB, HSL, Cubehelix, Lab and HCL (Lch).
Library home page: https://registry.npmjs.org/d3-color/-/d3-color-1.4.1.tgz
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
The d3-color module provides representations for various color spaces in the browser. Versions prior to 3.1.0 are vulnerable to a Regular expression Denial of Service. This issue has been patched in version 3.1.0. There are no known workarounds.
Publish Date: 2022-09-29
URL: WS-2022-0322
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-36jr-mh4h-2g58
Release Date: 2022-09-29
Fix Resolution: d3-color - 3.1.0
The text was updated successfully, but these errors were encountered: