OSSIndex / vulns

Report missing advisories and corrections on OSS Index
17 stars 12 forks source link

Incorrect vulnerability details for CVE-2022-2596 #318

Closed nicodemoraffaele closed 1 year ago

nicodemoraffaele commented 1 year ago

Vulnerability URL

https://ossindex.sonatype.org/vulnerability/CVE-2022-2596

Component URL

https://ossindex.sonatype.org/component/pkg:npm/node-fetch

Description Versions 2.x of node-fetch are not affected by the vulnerability. CVE list has been updated: https://github.com/CVEProject/cvelist/pull/6757/files Please refer also to: https://github.com/node-fetch/node-fetch/pull/1611

ken-duck commented 1 year ago

This appears to have been fixed: https://ossindex.sonatype.org/component/pkg:npm/node-fetch@2.6.7