-
Notifications
You must be signed in to change notification settings - Fork 65
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
jest-cli-24.9.0.tgz: 1 vulnerabilities (highest severity is: 6.1) #630
jest-cli-24.9.0.tgz: 1 vulnerabilities (highest severity is: 6.1) #630
Comments
The Request package (https://github.com/request/request) is deprecated, and there is a fix PR to this issue but it has not been merged: request/request#3444. However, i think we can request an exemption for this OUI CVE since the affected package that depends on request are all dev dependencies (jest-cli--testing, nodegit--asynchronous native bindings, yo--CLI tool for running Yeoman generators and node-sass), so i do not think it can be exposed by the SSRF vulnerability. @ananzh @joshuarrrr
|
agree. we could keep the issue open and wait for the fix to merge. we could pass to next on-call and keep monitor it until there is a new release. |
Vulnerable Library - jest-cli-24.9.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Found in HEAD commit: da8987297d043a87176cf037aa9b64d781bc29c5
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2023-28155
Vulnerable Library - request-2.88.0.tgz
Simplified HTTP request client.
Library home page: https://registry.npmjs.org/request/-/request-2.88.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
Found in HEAD commit: da8987297d043a87176cf037aa9b64d781bc29c5
Found in base branch: main
Vulnerability Details
The request package through 2.88.2 for Node.js and the @cypress/request package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).NOTE: The request package is no longer supported by the maintainer.
Publish Date: 2023-03-16
URL: CVE-2023-28155
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-p8p7-x288-28g6
Release Date: 2023-03-16
Fix Resolution: @cypress/request - 3.0.0
The text was updated successfully, but these errors were encountered: