This repository has been archived by the owner on Jun 27, 2022. It is now read-only.
WS-2019-0252 (Medium) detected in googleapis-38.0.0.tgz - autoclosed #150
Labels
security vulnerability
Security vulnerability detected by WhiteSource
WS-2019-0252 - Medium Severity Vulnerability
Vulnerable Library - googleapis-38.0.0.tgz
Google APIs Client Library for Node.js
Library home page: https://registry.npmjs.org/googleapis/-/googleapis-38.0.0.tgz
Path to dependency file: react-boilerplate/node_modules/googleapis/package.json
Path to vulnerable library: react-boilerplate/node_modules/googleapis/package.json
Dependency Hierarchy:
Found in HEAD commit: a7b9bd97d78d0efa86e884bcf048a44dc15eb607
Found in base branch: master
Vulnerability Details
googleapis versions before 39.1.0 are vulnerable to Improper Authorization. Setting credentials to one client may apply to all clients which may cause requests to be sent with the incorrect credentials.
Publish Date: 2019-02-19
URL: WS-2019-0252
CVSS 2 Score Details (5.0)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/791
Release Date: 2019-09-11
Fix Resolution: 39.1.0
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: