Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

WS-2019-0209 (Medium) detected in marked-0.5.2.tgz - autoclosed #59

Closed
mend-bolt-for-github bot opened this issue Sep 11, 2019 · 1 comment
Closed

Comments

@mend-bolt-for-github
Copy link
Contributor

WS-2019-0209 - Medium Severity Vulnerability

Vulnerable Library - marked-0.5.2.tgz

A markdown parser built for speed

Library home page: https://registry.npmjs.org/marked/-/marked-0.5.2.tgz

Path to dependency file: /tmp/ws-scm/source/FrontEnd/package.json

Path to vulnerable library: /source/FrontEnd/node_modules/marked/package.json

Dependency Hierarchy:

  • marked-0.5.2.tgz (Vulnerable Library)

Found in HEAD commit: 467bf78f693ed36f71ad535787eadd84b882dd7b

Vulnerability Details

marked before 0.7.0 vulnerable to Redos attack by he _label subrule that may significantly degrade parsing performance of malformed input.

Publish Date: 2019-09-05

URL: WS-2019-0209

CVSS 2 Score Details (5.0)

Base Score Metrics not available

Suggested Fix

Type: Upgrade version

Origin: https://www.npmjs.com/advisories/1076

Release Date: 2019-09-05

Fix Resolution: 0.7.0


Step up your Open Source Security Game with WhiteSource here

@mend-bolt-for-github mend-bolt-for-github bot changed the title WS-2019-0209 (Medium) detected in marked-0.5.2.tgz WS-2019-0209 (Medium) detected in marked-0.5.2.tgz - autoclosed May 7, 2022
@mend-bolt-for-github
Copy link
Contributor Author

✔️ This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

0 participants