Nexmo / comms-router

A server which allows you to route tasks to agents.
Apache License 2.0
19 stars 11 forks source link

buefy-0.6.6.tgz: 1 vulnerabilities (highest severity is: 6.1) #111

Open mend-for-github-com[bot] opened 2 years ago

mend-for-github-com[bot] commented 2 years ago
Vulnerable Library - buefy-0.6.6.tgz

Lightweight UI components for Vue.js based on Bulma

Library home page: https://registry.npmjs.org/buefy/-/buefy-0.6.6.tgz

Path to dependency file: /applications/gui/package.json

Path to vulnerable library: /applications/gui/node_modules/buefy/package.json

Found in HEAD commit: 4e5656db54be4b22481fe3774c2caeba51bac190

Vulnerabilities

CVE Severity CVSS Exploit Maturity EPSS Dependency Type Fixed in (buefy version) Remediation Possible** Reachability
WS-2019-0256 Medium 6.1 Not Defined buefy-0.6.6.tgz Direct 0.7.2

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

WS-2019-0256 ### Vulnerable Library - buefy-0.6.6.tgz

Lightweight UI components for Vue.js based on Bulma

Library home page: https://registry.npmjs.org/buefy/-/buefy-0.6.6.tgz

Path to dependency file: /applications/gui/package.json

Path to vulnerable library: /applications/gui/node_modules/buefy/package.json

Dependency Hierarchy: - :x: **buefy-0.6.6.tgz** (Vulnerable Library)

Found in HEAD commit: 4e5656db54be4b22481fe3774c2caeba51bac190

Found in base branch: main

### Vulnerability Details

In buefy, versions prior to 0.7.2 are vulnerable to Cross-Site Scripting when the autocomplete list renders user input as HTML without encoding.

Publish Date: 2019-09-11

URL: WS-2019-0256

### Threat Assessment

Exploit Maturity: Not Defined

EPSS:

### CVSS 3 Score Details (6.1)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None

For more information on CVSS3 Scores, click here.

### Suggested Fix

Type: Upgrade version

Origin: https://www.npmjs.com/advisories/747

Release Date: 2019-09-11

Fix Resolution: 0.7.2

:rescue_worker_helmet: Automatic Remediation will be attempted for this issue.

:rescue_worker_helmet:Automatic Remediation will be attempted for this issue.