joshnewton31080 / dvna

MIT License
0 stars 0 forks source link

CVE-2017-16004 (Medium) detected in node-serialize-0.0.4.tgz #14

Open mend-for-github-com[bot] opened 3 years ago

mend-for-github-com[bot] commented 3 years ago

CVE-2017-16004 - Medium Severity Vulnerability

Vulnerable Library - node-serialize-0.0.4.tgz

Serialize a object including it's function into a JSON.

Library home page: https://registry.npmjs.org/node-serialize/-/node-serialize-0.0.4.tgz

Path to dependency file: dvna/package.json

Path to vulnerable library: dvna/node_modules/node-serialize/package.json

Dependency Hierarchy: - :x: **node-serialize-0.0.4.tgz** (Vulnerable Library)

Found in HEAD commit: ebbe518de6103063656cb8a1c3d1040aacb09826

Found in base branch: main

Vulnerability Details

node-serialize ll versions can be abused to execute arbitrary code via an immediately invoked function expression

Publish Date: 2019-07-11

URL: CVE-2017-16004

CVSS 2 Score Details (5.0)

Base Score Metrics not available