Skip to content
This repository has been archived by the owner on Mar 8, 2024. It is now read-only.

nextra-1.1.0.tgz: 1 vulnerabilities (highest severity is: 5.3) #3

Closed
mend-bolt-for-github bot opened this issue Nov 6, 2022 · 0 comments
Closed
Labels
Mend: dependency security vulnerability Security vulnerability detected by Mend

Comments

@mend-bolt-for-github
Copy link

mend-bolt-for-github bot commented Nov 6, 2022

Vulnerable Library - nextra-1.1.0.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/got/package.json

Found in HEAD commit: 0f7cb9daf3eee4198e5a28d7d9a696f38a304ec4

Vulnerabilities

CVE Severity CVSS Dependency Type Fixed in (nextra version) Remediation Available
CVE-2022-33987 Medium 5.3 got-8.3.2.tgz Transitive N/A*

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the section "Details" below to see if there is a version of transitive dependency where vulnerability is fixed.

Details

CVE-2022-33987

Vulnerable Library - got-8.3.2.tgz

Simplified HTTP requests

Library home page: https://registry.npmjs.org/got/-/got-8.3.2.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/got/package.json

Dependency Hierarchy:

  • nextra-1.1.0.tgz (Root Library)
    • download-8.0.0.tgz
      • got-8.3.2.tgz (Vulnerable Library)

Found in HEAD commit: 0f7cb9daf3eee4198e5a28d7d9a696f38a304ec4

Found in base branch: production

Vulnerability Details

The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.

Publish Date: 2022-06-18

URL: CVE-2022-33987

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-33987

Release Date: 2022-06-18

Fix Resolution: got - 11.8.5,12.1.0

Step up your Open Source Security Game with Mend here

@mend-bolt-for-github mend-bolt-for-github bot added the Mend: dependency security vulnerability Security vulnerability detected by Mend label Nov 6, 2022
@mend-bolt-for-github mend-bolt-for-github bot changed the title nextra-1.1.0.tgz: 3 vulnerabilities (highest severity is: 7.5) nextra-1.1.0.tgz: 1 vulnerabilities (highest severity is: 5.3) Nov 7, 2022
@mend-bolt-for-github mend-bolt-for-github bot changed the title nextra-1.1.0.tgz: 1 vulnerabilities (highest severity is: 5.3) nextra-1.1.0.tgz: 3 vulnerabilities (highest severity is: 7.5) Nov 10, 2022
@mend-bolt-for-github mend-bolt-for-github bot changed the title nextra-1.1.0.tgz: 3 vulnerabilities (highest severity is: 7.5) nextra-1.1.0.tgz: 1 vulnerabilities (highest severity is: 5.3) Nov 10, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Mend: dependency security vulnerability Security vulnerability detected by Mend
Projects
None yet
Development

No branches or pull requests

1 participant