RetireJS / retire.js

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
https://retirejs.github.io/retire.js/
Other
3.6k stars 412 forks source link

Wrong CVE Scores #394

Closed DorShaer closed 1 year ago

DorShaer commented 1 year ago

CVE 2022-24785 and CVE-2022-31129 are both tagged as HIGH severity in any CVE DB in the world while you are specifying it as Medium severities. Please update it. Example sources: https://nvd.nist.gov/vuln/detail/CVE-2022-24785 https://nvd.nist.gov/vuln/detail/CVE-2022-31129

DorShaer commented 1 year ago

Big shout out to you guys for the quick fix, much thanks! appreciate it

eoftedal commented 1 year ago

Thanks for reporting!