Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[FP]: npm loader-utils@1.4.1 #5044

Closed
Felk opened this issue Nov 10, 2022 · 3 comments
Closed

[FP]: npm loader-utils@1.4.1 #5044

Felk opened this issue Nov 10, 2022 · 3 comments

Comments

@Felk
Copy link

Felk commented Nov 10, 2022

Package URl

pkg:npm/loader-utils@1.4.1

CPE

cpe:2.3:a:webpack.js:loader-utils:1.4.1:::::::*

CVE

CVE-2022-37601

ODC Integration

{"label"=>"Maven Plugin"}

ODC Version

7.3.0

Description

CVE-2022-37601 was also fixed in loader-utils@1.4.1 via backport, as per webpack/loader-utils#218 and https://github.com/webpack/loader-utils/releases/tag/v1.4.1

@Felk Felk added the FP Report label Nov 10, 2022
@github-actions
Copy link
Contributor

Npm Coordinates

npm -i loader-utils@1.4.1

Suppression rule:

<suppress base="true">
   <notes><![CDATA[
   FP per issue #5044
   ]]></notes>
   <packageUrl regex="true">^pkg:npm/loader-utils@.*$</packageUrl>
   <cpe>cpe:/a:webpack.js:loader-utils</cpe>
</suppress>

Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/3437067363

@github-actions github-actions bot added the npm label Nov 10, 2022
@aikebah
Copy link
Collaborator

aikebah commented Nov 20, 2022

@Felk This was due to the vulnerability data at the NIST NVD datastreams. It has been updated meanwhile (at 11/17/2022 9:14:18 AM), but in future you can directly reach out to them using the "[Are we missing a CPE here? Please let us know]" link of the NVD page of the vulnerability (https://nvd.nist.gov/vuln/detail/CVE-2022-37601)

@aikebah aikebah closed this as not planned Won't fix, can't repro, duplicate, stale Nov 20, 2022
@Felk
Copy link
Author

Felk commented Nov 21, 2022

ah, good to know thanks!

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Dec 30, 2024
# for free to subscribe to this conversation on GitHub. Already have an account? #.
Projects
None yet
Development

No branches or pull requests

2 participants