turkdevops / grafana

The tool for beautiful monitoring and metric analytics & dashboards for Graphite, InfluxDB & Prometheus & More
https://grafana.com
Apache License 2.0
1 stars 0 forks source link

CVE-2021-3801 (Medium) detected in prismjs-1.24.0.tgz, prismjs-1.17.1.tgz - autoclosed #524

Closed mend-bolt-for-github[bot] closed 3 years ago

mend-bolt-for-github[bot] commented 3 years ago

CVE-2021-3801 - Medium Severity Vulnerability

Vulnerable Libraries - prismjs-1.24.0.tgz, prismjs-1.17.1.tgz

prismjs-1.24.0.tgz

Lightweight, robust, elegant syntax highlighting. A spin-off project from Dabblet.

Library home page: https://registry.npmjs.org/prismjs/-/prismjs-1.24.0.tgz

Path to dependency file: grafana/package.json

Path to vulnerable library: grafana/node_modules/prismjs

Dependency Hierarchy: - :x: **prismjs-1.24.0.tgz** (Vulnerable Library)

prismjs-1.17.1.tgz

Lightweight, robust, elegant syntax highlighting. A spin-off project from Dabblet.

Library home page: https://registry.npmjs.org/prismjs/-/prismjs-1.17.1.tgz

Path to dependency file: grafana/package.json

Path to vulnerable library: grafana/node_modules/prismjs

Dependency Hierarchy: - @grafana/ui-6.7.0-pre.tgz (Root Library) - addon-actions-5.3.9.tgz - components-5.3.9.tgz - react-syntax-highlighter-11.0.2.tgz - refractor-2.10.0.tgz - :x: **prismjs-1.17.1.tgz** (Vulnerable Library)

Found in base branch: datasource-meta

Vulnerability Details

prism is vulnerable to Inefficient Regular Expression Complexity

Publish Date: 2021-09-15

URL: CVE-2021-3801

CVSS 3 Score Details (5.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: N/A - Attack Complexity: N/A - Privileges Required: N/A - User Interaction: N/A - Scope: N/A - Impact Metrics: - Confidentiality Impact: N/A - Integrity Impact: N/A - Availability Impact: N/A

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with WhiteSource here

mend-bolt-for-github[bot] commented 3 years ago

:heavy_check_mark: This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.