Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-37603 (High) detected in loader-utils-2.0.3 #452

Closed
jovancacvetkovic opened this issue Jan 23, 2023 · 2 comments
Closed

CVE-2022-37603 (High) detected in loader-utils-2.0.3 #452

jovancacvetkovic opened this issue Jan 23, 2023 · 2 comments
Labels
bug Something isn't working

Comments

@jovancacvetkovic
Copy link
Contributor

CVE-2022-46175 - High Severity Vulnerability

Vulnerability Library - loader-utils - 2.0.3

loader-utils - 2.0.3 (current version)
Found in base branch: main

CVSS 3 Score Details - (7.5)

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

Suggested Fix

Type: Upgrade version

Release Date: Oct 6, 2022

Fix Resolution: loader-utils - 2.0.4

More Info

loader-utils issue resolved with #213

@AWSHurneyt
Copy link
Collaborator

For reference, here's the PR addressing CVE-2022-46175
#453

@lezzago
Copy link
Member

lezzago commented Feb 2, 2023

This issue has been resolved as the PR has been merged

@lezzago lezzago closed this as completed Feb 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

4 participants