sshivananda / ts-sqs-consumer

Typescript based sqs consumer
MIT License
3 stars 2 forks source link

CVE-2021-46703 (High) detected in RazorEngine-3.4.1.0.dll #128

Open mend-bolt-for-github[bot] opened 2 years ago

mend-bolt-for-github[bot] commented 2 years ago

CVE-2021-46703 - High Severity Vulnerability

Vulnerable Library - RazorEngine-3.4.1.0.dll

RazorEngine.Core

Library home page: https://api.nuget.org/packages/razorengine.3.4.1.nupkg

Path to vulnerable library: /node_modules/gherkin/berp/RazorEngine.dll

Dependency Hierarchy: - :x: **RazorEngine-3.4.1.0.dll** (Vulnerable Library)

Found in base branch: master

Vulnerability Details

** UNSUPPORTED WHEN ASSIGNED ** In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Publish Date: 2022-03-06

URL: CVE-2021-46703

CVSS 3 Score Details (9.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2021-46703

Release Date: 2022-03-06

Fix Resolution: Bddify - 0.3.1;SpecRun - 1.0.0;S-money.Api.Wrapper - 1.0.2.3-alpha;graze - 5.5.0;ExtentReports - 2.40.1-beta4;Wolfpack.Contrib.Publishers.Email - 3.0.20,3.0.10-pre;Zapos.Common - 1.13.1.38,1.13.1;ExcelDnaDoc - 0.1.3-alpha,1.5.0-rc;FSharp.Formatting.CommandTool - 2.7.5,2.6.2;gcRazor - 1.0.8;BitFrame - 0.0.0.4;Zapos.Printers.Gembox - 1.13.1,1.13.1.41;FSharp.Formatting - 2.6.2,2.7.5;Cake.MarkdownToPdf - 0.4.0,0.3.0;Zapos.Constructors.Razor - 1.13.1,1.13.1.41;BDDify - 0.2.0;bddify - 0.3.0;apitize - 1.0.10;Berp - 1.3.0;Yaaf.AdvancedBuilding - 0.5.0;SpecRun.Runner - 1.6.0-rc005;Postal-Custom.Mvc5 - 1.0.1


Step up your Open Source Security Game with Mend here