satyamchaurasiapersistent / JavaVulnerableLab

lab
0 stars 0 forks source link

CX: CVE-2022-38900 in Npm-decode-uri-component and 0.2.2 @ JavaVulnerableLab.master #161

Open satyamchaurasiapersistent opened 1 year ago

satyamchaurasiapersistent commented 1 year ago

Description

decode-uri-component is vulnerable to Improper Input Validation resulting in DoS.

HIGH Vulnerable Package issue exists @ decode-uri-component in branch master

Vulnerability ID: CVE-2022-38900

Package Name: decode-uri-component

Severity: HIGH

CVSS Score: 7.5

Publish Date: 2022-11-28T05:23:00

Current Package Version: 0.2.2

Remediation Upgrade Recommendation: 0.3.0

Link To SCA

Reference – NVD link