Open mend-for-github-com[bot] opened 4 years ago
Node.js JavaScript runtime :sparkles::turtle::rocket::sparkles:
Library home page: https://github.com/nodejs/node.git
brace-expansion before 1.1.7 are vulnerable to a regular expression denial of service.
Publish Date: 2020-07-21
URL: CVE-2017-16032
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: High - Privileges Required: Low - User Interaction: Required - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: High
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/338
Release Date: 2020-07-21
Fix Resolution: v1.1.7
CVE-2017-16032 - Medium Severity Vulnerability
Vulnerable Library - nodev10.10.0
Node.js JavaScript runtime :sparkles::turtle::rocket::sparkles:
Library home page: https://github.com/nodejs/node.git
Vulnerable Source Files (0)
Vulnerability Details
brace-expansion before 1.1.7 are vulnerable to a regular expression denial of service.
Publish Date: 2020-07-21
URL: CVE-2017-16032
CVSS 3 Score Details (5.5)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: High - Privileges Required: Low - User Interaction: Required - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/338
Release Date: 2020-07-21
Fix Resolution: v1.1.7