Dashbrd / ngx-image-dimension

0 stars 0 forks source link

WS-2019-0231 (Medium) detected in adm-zip-0.4.4.tgz - autoclosed #67

Closed mend-bolt-for-github[bot] closed 2 years ago

mend-bolt-for-github[bot] commented 3 years ago

WS-2019-0231 - Medium Severity Vulnerability

Vulnerable Library - adm-zip-0.4.4.tgz

A Javascript implementation of zip for nodejs. Allows user to create or extract zip files both in memory or to/from disk

Library home page: https://registry.npmjs.org/adm-zip/-/adm-zip-0.4.4.tgz

Path to dependency file: /ngx-image-dimension/package.json

Path to vulnerable library: ngx-image-dimension/node_modules/webdriver-js-extender/node_modules/adm-zip/package.json

Dependency Hierarchy: - protractor-5.1.2.tgz (Root Library) - webdriver-js-extender-1.0.0.tgz - selenium-webdriver-2.53.3.tgz - :x: **adm-zip-0.4.4.tgz** (Vulnerable Library)

Vulnerability Details

adm-zip versions before 0.4.9 are vulnerable to Arbitrary File Write due to extraction of a specifically crafted archive that contains path traversal filenames

Publish Date: 2018-04-22

URL: WS-2019-0231

CVSS 2 Score Details (5.0)

Base Score Metrics not available

Suggested Fix

Type: Upgrade version

Origin: https://www.npmjs.com/advisories/994

Release Date: 2019-09-09

Fix Resolution: 0.4.9


Step up your Open Source Security Game with WhiteSource here

mend-bolt-for-github[bot] commented 2 years ago

:heavy_check_mark: This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.