billmcchesney1 / foxtrot

A store abstraction and analytics system for real-time event data.
Apache License 2.0
0 stars 0 forks source link

CVE-2016-1000241 (High) detected in handlebars-1.3.0.js - autoclosed #375

Closed mend-for-github-com[bot] closed 1 year ago

mend-for-github-com[bot] commented 1 year ago

CVE-2016-1000241 - High Severity Vulnerability

Vulnerable Library - handlebars-1.3.0.js

Handlebars provides the power necessary to let you build semantic templates effectively with no frustration

Library home page: https://cdnjs.cloudflare.com/ajax/libs/handlebars.js/1.3.0/handlebars.js

Path to dependency file: /foxtrot-server/src/main/resources/console/cluster/index.htm

Path to vulnerable library: /foxtrot-server/src/main/resources/console/js/handlebars-v1.3.0.js,/foxtrot-server/src/main/resources/console/cluster/../js/handlebars-v1.3.0.js,/foxtrot-server/target/classes/console/fql/../js/handlebars-v1.3.0.js,/foxtrot-server/target/classes/console/echo/js/handlebars-v1.3.0.js,/foxtrot-server/target/classes/console/cluster/../js/handlebars-v1.3.0.js,/foxtrot-server/src/main/resources/console/echo/js/handlebars-v1.3.0.js,/foxtrot-server/target/classes/console/echo/fql/../js/handlebars-v1.3.0.js,/foxtrot-server/target/classes/console/js/handlebars-v1.3.0.js,/foxtrot-server/src/main/resources/console/echo/cluster/../js/handlebars-v1.3.0.js,/foxtrot-server/target/classes/console/echo/cluster/../js/handlebars-v1.3.0.js,/foxtrot-server/src/main/resources/console/js/handlebars-v1.3.0.js,/foxtrot-server/src/main/resources/console/echo/fql/../js/handlebars-v1.3.0.js,/foxtrot-server/src/main/resources/console/echo/js/handlebars-v1.3.0.js,/foxtrot-server/target/classes/console/js/handlebars-v1.3.0.js,/foxtrot-server/target/classes/console/echo/js/handlebars-v1.3.0.js,/foxtrot-server/src/main/resources/console/fql/../js/handlebars-v1.3.0.js

Dependency Hierarchy: - :x: **handlebars-1.3.0.js** (Vulnerable Library)

Found in HEAD commit: ffb8a6014463ce8aac1bf6e7dc9a23fc4a2a8adc

Found in base branch: master

Vulnerability Details

pivottable before 2.0.0 is vulnerable to Cross-Site Scripting (XSS) vulnerability, due to a new mechanism used to render JSON elements.

Publish Date: 2020-07-21

URL: CVE-2016-1000241

CVSS 3 Score Details (7.3)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/advisories/GHSA-cjj8-wfrx-jqcf

Release Date: 2020-07-21

Fix Resolution: pivottable - 2.0.0

mend-for-github-com[bot] commented 1 year ago

:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.