joshjohanning-org / ghas-demo

this is a sample security scanning repo
1 stars 4 forks source link

Update package.json with vulnerable package #18

Open joshjohanning opened 2 years ago

joshjohanning commented 2 years ago

Adding tar 2.2.2

github-actions[bot] commented 1 year ago

Dependency Review

The following issues were found:

See the Details below.

Vulnerabilities

frontend/package.json

NameVersionVulnerabilitySeverity
tar2.2.2Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoninghigh
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitizationhigh
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic linkshigh
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic linkshigh
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitizationhigh

Scanned Manifest Files

.github/workflows/dependency-review.yml
  • actions/dependency-review-action@3
  • actions/dependency-review-action@2
frontend/package.json
  • tar@2.2.2