reymon359 / Turismo-Torrevieja

[ABPGC17] Proyecto de Gestión de Contenidos del grupo Xtres del ABP 2017/18
0 stars 0 forks source link

WS-2018-0103 (Medium) detected in stringstream-0.0.5.tgz #30

Open mend-bolt-for-github[bot] opened 5 years ago

mend-bolt-for-github[bot] commented 5 years ago

WS-2018-0103 - Medium Severity Vulnerability

Vulnerable Library - stringstream-0.0.5.tgz

Encode and decode streams into string streams

Library home page: https://registry.npmjs.org/stringstream/-/stringstream-0.0.5.tgz

Path to dependency file: /Turismo-Torrevieja/package.json

Path to vulnerable library: /tmp/git/Turismo-Torrevieja/node_modules/stringstream/package.json

Dependency Hierarchy: - cli-1.6.1.tgz (Root Library) - less-2.7.3.tgz - request-2.81.0.tgz - :x: **stringstream-0.0.5.tgz** (Vulnerable Library)

Found in HEAD commit: 5fe809a2e7cf19f24da932e71d58c622ec363c70

Vulnerability Details

All versions of stringstream are vulnerable to out-of-bounds read as it allocates uninitialized Buffers when number is passed in input stream on Node.js 4.x and below.

Publish Date: 2018-05-16

URL: WS-2018-0103

CVSS 2 Score Details (5.2)

Base Score Metrics not available

Suggested Fix

Type: Upgrade version

Origin: https://www.npmjs.com/advisories/664/versions

Release Date: 2019-06-05

Fix Resolution: 0.0.6,1.0.0


Step up your Open Source Security Game with WhiteSource here