@kleros/scout-snap-1.3.4.tgz: 1 vulnerabilities (highest severity is: 7.5) #66
Labels
dependencies
Pull requests that update a dependency file
Mend: dependency security vulnerability
Security vulnerability detected by Mend
Type: Security🛡️
Custom label for issues opened by WhiteSource
Path to dependency file: /package.json
Path to vulnerable library: /.yarn/cache/fast-xml-parser-npm-4.4.0-5d120445d5-ad33a4b516.zip,/package.json
Found in HEAD commit: 483eb6afa43e7ef60f53348ac2115f38b8ba99a7
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - fast-xml-parser-4.4.0.tgz
Library home page: https://registry.npmjs.org/fast-xml-parser/-/fast-xml-parser-4.4.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /.yarn/cache/fast-xml-parser-npm-4.4.0-5d120445d5-ad33a4b516.zip,/package.json
Dependency Hierarchy:
Found in HEAD commit: 483eb6afa43e7ef60f53348ac2115f38b8ba99a7
Found in base branch: master
Vulnerability Details
fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.
Publish Date: 2024-07-29
URL: CVE-2024-41818
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-mpg4-rc92-vx8v
Release Date: 2024-07-29
Fix Resolution: fast-xml-parser - 4.4.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: