issues
search
joshjohanning-org
/
ghas-demo
this is a sample security scanning repo
1
stars
4
forks
source link
Update package.json with vulnerable package
#18
Open
joshjohanning
opened
2 years ago
joshjohanning
commented
2 years ago
Adding
tar 2.2.2
github-actions[bot]
commented
1 year ago
Dependency Review
The following issues were found:
❌ 1 vulnerable package(s)
✅ 0 package(s) with incompatible licenses
✅ 0 package(s) with invalid SPDX license definitions
✅ 0 package(s) with unknown licenses.
See the Details below.
Vulnerabilities
frontend/package.json
Name
Version
Vulnerability
Severity
tar
2.2.2
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning
high
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
high
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
high
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
high
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
high
Scanned Manifest Files
.github/workflows/dependency-review.yml
actions/dependency-review-action@3
actions/dependency-review-action@2
frontend/package.json
tar@2.2.2
Adding
tar 2.2.2