iamkishan98 / E-voting-using-blockchain

Decentralized online vorting application built with blockchain
2 stars 0 forks source link

WS-2015-0018 (Medium) detected in multiple libraries - autoclosed #56

Closed mend-bolt-for-github[bot] closed 2 years ago

mend-bolt-for-github[bot] commented 5 years ago

WS-2015-0018 - Medium Severity Vulnerability

Vulnerable Libraries - semver-1.0.14.tgz, semver-3.0.1.tgz, semver-2.1.0.tgz, semver-2.2.1.tgz, semver-2.3.2.tgz

semver-1.0.14.tgz

The semantic version parser used by npm.

Library home page: https://registry.npmjs.org/semver/-/semver-1.0.14.tgz

Path to dependency file: /E-voting-using-blockchain/evoting app/src/bower_components/jquery-ui/package.json

Path to vulnerable library: /tmp/git/E-voting-using-blockchain/evoting app/src/bower_components/select2/node_modules/grunt-lib-phantomjs/node_modules/semver/package.json,/tmp/git/E-voting-using-blockchain/evoting app/src/bower_components/select2/node_modules/grunt-lib-phantomjs/node_modules/semver/package.json

Dependency Hierarchy: - grunt-contrib-qunit-0.4.0.tgz (Root Library) - grunt-lib-phantomjs-0.5.0.tgz - :x: **semver-1.0.14.tgz** (Vulnerable Library)

semver-3.0.1.tgz

The semantic version parser used by npm.

Library home page: http://registry.npmjs.org/semver/-/semver-3.0.1.tgz

Path to dependency file: /E-voting-using-blockchain/evoting app/src/bower_components/chart.js/package.json

Path to vulnerable library: /E-voting-using-blockchain/evoting app/src/bower_components/chart.js/node_modules/semver/package.json

Dependency Hierarchy: - :x: **semver-3.0.1.tgz** (Vulnerable Library)

semver-2.1.0.tgz

The semantic version parser used by npm.

Library home page: http://registry.npmjs.org/semver/-/semver-2.1.0.tgz

Path to dependency file: /E-voting-using-blockchain/evoting app/src/bower_components/morris.js/package.json

Path to vulnerable library: /tmp/git/E-voting-using-blockchain/evoting app/src/bower_components/morris.js/node_modules/semver/package.json

Dependency Hierarchy: - bower-1.2.8.tgz (Root Library) - :x: **semver-2.1.0.tgz** (Vulnerable Library)

semver-2.2.1.tgz

The semantic version parser used by npm.

Library home page: https://registry.npmjs.org/semver/-/semver-2.2.1.tgz

Path to dependency file: /E-voting-using-blockchain/evoting app/src/bower_components/select2/package.json

Path to vulnerable library: /tmp/git/E-voting-using-blockchain/evoting app/src/bower_components/select2/node_modules/npm-registry/node_modules/semver/package.json

Dependency Hierarchy: - shrinkwrap-0.4.0.tgz (Root Library) - npm-registry-0.1.13.tgz - :x: **semver-2.2.1.tgz** (Vulnerable Library)

semver-2.3.2.tgz

The semantic version parser used by npm.

Library home page: https://registry.npmjs.org/semver/-/semver-2.3.2.tgz

Path to dependency file: /E-voting-using-blockchain/evoting app/src/bower_components/chart.js/package.json

Path to vulnerable library: /tmp/git/E-voting-using-blockchain/evoting app/src/bower_components/morris.js/node_modules/update-notifier/node_modules/semver/package.json,/tmp/git/E-voting-using-blockchain/evoting app/src/bower_components/morris.js/node_modules/update-notifier/node_modules/semver/package.json

Dependency Hierarchy: - bower-1.2.8.tgz (Root Library) - update-notifier-0.1.10.tgz - :x: **semver-2.3.2.tgz** (Vulnerable Library)

Found in HEAD commit: 3c02898f89d78283ce791eb1b53b2b5a667681ad

Vulnerability Details

Semver is vulnerable to regular expression denial of service (ReDoS) when extremely long version strings are parsed.

Publish Date: 2015-04-04

URL: WS-2015-0018

CVSS 2 Score Details (5.3)

Base Score Metrics not available

Suggested Fix

Type: Upgrade version

Origin: https://nodesecurity.io/advisories/31

Release Date: 2015-04-04

Fix Resolution: Update to a version 4.3.2 or greater


Step up your Open Source Security Game with WhiteSource here

mend-bolt-for-github[bot] commented 2 years ago

:heavy_check_mark: This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.