You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.
all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.
xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the proto property to be edited.
Vulnerable Library - resize-img-1.1.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/jimp/node_modules/jpeg-js/package.json
Found in HEAD commit: a6f8a4191628c69dae14cb7888e24a253948b14a
Vulnerabilities
Unreachable
Unreachable
Unreachable
Unreachable
Unreachable
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2022-25851
Vulnerable Library - jpeg-js-0.2.0.tgz
A pure javascript JPEG encoder and decoder
Library home page: https://registry.npmjs.org/jpeg-js/-/jpeg-js-0.2.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/jimp/node_modules/jpeg-js/package.json
Dependency Hierarchy:
Found in HEAD commit: a6f8a4191628c69dae14cb7888e24a253948b14a
Found in base branch: master
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.
Publish Date: 2022-06-10
URL: CVE-2022-25851
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2022-06-10
Fix Resolution: jpeg-js - 0.4.4
CVE-2020-7753
Vulnerable Library - trim-0.0.1.tgz
Trim string whitespace
Library home page: https://registry.npmjs.org/trim/-/trim-0.0.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/trim/package.json
Dependency Hierarchy:
Found in HEAD commit: a6f8a4191628c69dae14cb7888e24a253948b14a
Found in base branch: master
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().
Publish Date: 2020-10-27
URL: CVE-2020-7753
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2020-10-27
Fix Resolution (trim): 0.0.3
Direct dependency fix Resolution (resize-img): 2.0.0
⛑️ Automatic Remediation will be attempted for this issue.
CVE-2020-7661
Vulnerable Library - url-regex-3.2.0.tgz
Regular expression for matching URLs
Library home page: https://registry.npmjs.org/url-regex/-/url-regex-3.2.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/url-regex/package.json
Dependency Hierarchy:
Found in HEAD commit: a6f8a4191628c69dae14cb7888e24a253948b14a
Found in base branch: master
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service.
Publish Date: 2020-06-04
URL: CVE-2020-7661
CVSS 3 Score Details (7.5)
Base Score Metrics:
CVE-2020-8175
Vulnerable Library - jpeg-js-0.2.0.tgz
A pure javascript JPEG encoder and decoder
Library home page: https://registry.npmjs.org/jpeg-js/-/jpeg-js-0.2.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/jimp/node_modules/jpeg-js/package.json
Dependency Hierarchy:
Found in HEAD commit: a6f8a4191628c69dae14cb7888e24a253948b14a
Found in base branch: master
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
Uncontrolled resource consumption in
jpeg-js
before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.Publish Date: 2020-07-24
URL: CVE-2020-8175
CVSS 3 Score Details (5.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8175
Release Date: 2020-07-24
Fix Resolution: 0.4.0
CVE-2023-0842
Vulnerable Library - xml2js-0.4.19.tgz
Simple XML to JavaScript object converter.
Library home page: https://registry.npmjs.org/xml2js/-/xml2js-0.4.19.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/xml2js/package.json
Dependency Hierarchy:
Found in HEAD commit: a6f8a4191628c69dae14cb7888e24a253948b14a
Found in base branch: master
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the proto property to be edited.
Publish Date: 2023-04-05
URL: CVE-2023-0842
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2023-0842
Release Date: 2023-04-05
Fix Resolution (xml2js): 0.5.0
Direct dependency fix Resolution (resize-img): 2.0.0
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.
The text was updated successfully, but these errors were encountered: