billmcchesney1 / concord

Concord - workflow orchestration and continuous deployment management
https://concord.walmartlabs.com
Other
0 stars 0 forks source link

CVE-2016-1000241 (High) detected in handlebars-4.1.2.min.js - autoclosed #189

Closed mend-for-github-com[bot] closed 1 year ago

mend-for-github-com[bot] commented 1 year ago

CVE-2016-1000241 - High Severity Vulnerability

Vulnerable Library - handlebars-4.1.2.min.js

Handlebars provides the power necessary to let you build semantic templates effectively with no frustration

Library home page: https://cdnjs.cloudflare.com/ajax/libs/handlebars.js/4.1.2/handlebars.min.js

Path to dependency file: /examples/custom_form/forms/myForm/index.html

Path to vulnerable library: /examples/custom_form/forms/myForm/index.html,/examples/forms_wizard/forms/userWarning/index.html,/examples/form_l10n/forms/myOtherForm/index.html,/examples/dynamic_form_values/forms/myForm/index.html,/examples/forms_wizard/forms/userData/index.html

Dependency Hierarchy: - :x: **handlebars-4.1.2.min.js** (Vulnerable Library)

Found in base branch: master

Vulnerability Details

pivottable before 2.0.0 is vulnerable to Cross-Site Scripting (XSS) vulnerability, due to a new mechanism used to render JSON elements.

Publish Date: 2020-07-21

URL: CVE-2016-1000241

CVSS 3 Score Details (7.3)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/advisories/GHSA-cjj8-wfrx-jqcf

Release Date: 2020-07-21

Fix Resolution: pivottable - 2.0.0

mend-for-github-com[bot] commented 1 year ago

:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.