Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

CVE-2021-35065 (High) detected in glob-parent-6.0.0.tgz - autoclosed #1103

Closed
mend-for-github-com bot opened this issue Jan 5, 2022 · 1 comment
Closed
Labels
cve Security vulnerabilities detected by Dependabot or Mend medium severity Medium severity CVE Mend: dependency security vulnerability Security vulnerability detected by Mend

Comments

@mend-for-github-com
Copy link

mend-for-github-com bot commented Jan 5, 2022

CVE-2021-35065 - High Severity Vulnerability

Vulnerable Library - glob-parent-6.0.0.tgz

Extract the non-magic parent path from a glob string.

Library home page: https://registry.npmjs.org/glob-parent/-/glob-parent-6.0.0.tgz

Dependency Hierarchy:

  • @osd/config-schema-1.0.0.tgz (Root Library)
    • tsd-0.16.0.tgz
      • globby-11.0.4.tgz
        • fast-glob-3.2.2.tgz
          • glob-parent-6.0.0.tgz (Vulnerable Library)

Found in HEAD commit: d48d001fdc515eaa44403a909ff4628a3902915c

Found in base branch: main

Vulnerability Details

The package glob-parent before 6.0.1 are vulnerable to Regular Expression Denial of Service (ReDoS)

Publish Date: 2021-06-22

URL: CVE-2021-35065

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: gulpjs/glob-parent#49

Release Date: 2021-06-22

Fix Resolution: glob-parent - 6.0.1

@mend-for-github-com mend-for-github-com bot added the Mend: dependency security vulnerability Security vulnerability detected by Mend label Jan 5, 2022
@seanneumann seanneumann added the medium severity Medium severity CVE label Jan 5, 2022
@tmarkley tmarkley added the cve Security vulnerabilities detected by Dependabot or Mend label Jan 6, 2022
@mend-for-github-com mend-for-github-com bot changed the title CVE-2021-35065 (Medium) detected in glob-parent-6.0.0.tgz CVE-2021-35065 (High) detected in glob-parent-6.0.0.tgz Jan 7, 2022
@mend-for-github-com mend-for-github-com bot changed the title CVE-2021-35065 (High) detected in glob-parent-6.0.0.tgz CVE-2021-35065 (High) detected in glob-parent-6.0.0.tgz - autoclosed Jan 14, 2022
@mend-for-github-com
Copy link
Author

✔️ This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.

AMoo-Miki pushed a commit to AMoo-Miki/OpenSearch-Dashboards that referenced this issue Feb 10, 2022
ananzh added a commit to ananzh/OpenSearch-Dashboards that referenced this issue Mar 30, 2023
Issue Resolve
opensearch-project#1103

Signed-off-by: Anan Zhuang <ananzh@amazon.com>
ananzh added a commit to ananzh/OpenSearch-Dashboards that referenced this issue Mar 30, 2023
Issue Resolve
opensearch-project#1103

Signed-off-by: Anan Zhuang <ananzh@amazon.com>
ananzh added a commit to ananzh/OpenSearch-Dashboards that referenced this issue Mar 30, 2023
Issue Resolve
opensearch-project#1103

Signed-off-by: Anan Zhuang <ananzh@amazon.com>
joshuarrrr added a commit that referenced this issue May 9, 2023
* [CVE-2021-35065][1.x] Bump glob-parent from 6.0.0 to 6.0.2

Issue Resolve
#1103

Signed-off-by: Anan Zhuang <ananzh@amazon.com>

* Update package.json

Co-authored-by: Josh Romero <rmerqg@amazon.com>
Signed-off-by: Anan Zhuang <ananzh@amazon.com>

---------

Signed-off-by: Anan Zhuang <ananzh@amazon.com>
Co-authored-by: Josh Romero <rmerqg@amazon.com>
opensearch-trigger-bot bot pushed a commit that referenced this issue May 9, 2023
* [CVE-2021-35065][1.x] Bump glob-parent from 6.0.0 to 6.0.2

Issue Resolve
#1103

Signed-off-by: Anan Zhuang <ananzh@amazon.com>

* Update package.json

Co-authored-by: Josh Romero <rmerqg@amazon.com>
Signed-off-by: Anan Zhuang <ananzh@amazon.com>

---------

Signed-off-by: Anan Zhuang <ananzh@amazon.com>
Co-authored-by: Josh Romero <rmerqg@amazon.com>
(cherry picked from commit 3dfd699)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

# Conflicts:
#	CHANGELOG.md
manasvinibs pushed a commit that referenced this issue May 11, 2023
…4005)

* [CVE-2021-35065][1.x] Bump glob-parent from 6.0.0 to 6.0.2

Issue Resolve
#1103

Signed-off-by: Anan Zhuang <ananzh@amazon.com>

* Update package.json

Co-authored-by: Josh Romero <rmerqg@amazon.com>
Signed-off-by: Anan Zhuang <ananzh@amazon.com>

---------

Signed-off-by: Anan Zhuang <ananzh@amazon.com>
Co-authored-by: Josh Romero <rmerqg@amazon.com>
(cherry picked from commit 3dfd699)
Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

# Conflicts:
#	CHANGELOG.md

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
cve Security vulnerabilities detected by Dependabot or Mend medium severity Medium severity CVE Mend: dependency security vulnerability Security vulnerability detected by Mend
Projects
None yet
Development

No branches or pull requests

2 participants