OSSIndex / vulns

Report missing advisories and corrections on OSS Index
17 stars 12 forks source link

Incorrect vulnerability details #218

Open alitheg opened 2 years ago

alitheg commented 2 years ago

Vulnerability URL Provide the URL to the vulnerability. For example:

https://ossindex.sonatype.org/vulnerability/e391a58d-4a81-448b-8ffc-e19016807d73?component-type=npm&component-name=btoa

Component URL Provide the URL to the component. For example:

https://ossindex.sonatype.org/component/pkg:npm/btoa@1.2.1

Description As far as I can tell (from following the links to the npm advisory: https://www.npmjs.com/advisories/646), this vulnerability is only exploitable on NodeJS 4.x. While it's valid, perhaps there should be some note that this is the case, so that it's easily excused in audit findings.