Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FP]: npm loader-utils@1.4.1 #5044

Closed
Felk opened this issue Nov 10, 2022 · 3 comments
Closed

[FP]: npm loader-utils@1.4.1 #5044

Felk opened this issue Nov 10, 2022 · 3 comments

Comments

@Felk
Copy link

Felk commented Nov 10, 2022

Package URl

pkg:npm/loader-utils@1.4.1

CPE

cpe:2.3:a:webpack.js:loader-utils:1.4.1:::::::*

CVE

CVE-2022-37601

ODC Integration

{"label"=>"Maven Plugin"}

ODC Version

7.3.0

Description

CVE-2022-37601 was also fixed in loader-utils@1.4.1 via backport, as per webpack/loader-utils#218 and https://github.com/webpack/loader-utils/releases/tag/v1.4.1

@Felk Felk added the FP Report label Nov 10, 2022
@github-actions
Copy link
Contributor

Npm Coordinates

npm -i loader-utils@1.4.1

Suppression rule:

<suppress base="true">
   <notes><![CDATA[
   FP per issue #5044
   ]]></notes>
   <packageUrl regex="true">^pkg:npm/loader-utils@.*$</packageUrl>
   <cpe>cpe:/a:webpack.js:loader-utils</cpe>
</suppress>

Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/3437067363

@github-actions github-actions bot added the npm label Nov 10, 2022
@aikebah
Copy link
Collaborator

aikebah commented Nov 20, 2022

@Felk This was due to the vulnerability data at the NIST NVD datastreams. It has been updated meanwhile (at 11/17/2022 9:14:18 AM), but in future you can directly reach out to them using the "[Are we missing a CPE here? Please let us know]" link of the NVD page of the vulnerability (https://nvd.nist.gov/vuln/detail/CVE-2022-37601)

@aikebah aikebah closed this as not planned Won't fix, can't repro, duplicate, stale Nov 20, 2022
@Felk
Copy link
Author

Felk commented Nov 21, 2022

ah, good to know thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants