📂 Vulnerable Library - terser-webpack-plugin-4.2.3.tgz
Terser plugin for webpack
Findings
| Finding |
Severity |
🎯 CVSS |
Exploit Maturity |
EPSS |
Library |
Type |
Fixed in |
Remediation Available |
Reachability |
| CVE-289561-266276 |
🟣 Critical |
9.8 |
N/A |
N/A |
inherits-2.0.4.tgz |
Transitive |
N/A |
❌ |
|
| CVE-2022-3517 |
🔴 High |
8.7 |
Not Defined |
< 1% |
minimatch-3.0.4.tgz |
Transitive |
N/A |
❌ |
Reachable |
Details
🟣CVE-289561-266276
Vulnerable Library - inherits-2.0.4.tgz
Browser-friendly inheritance fully compatible with standard node.js inherits()
Library home page: https://registry.npmjs.org/inherits/-/inherits-2.0.4.tgz
Dependency Hierarchy:
-
mongoose-5.13.14.tgz (Root Library)
- mongodb-3.7.3.tgz
- bl-2.2.1.tgz
- readable-stream-2.3.7.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
-
jest-circus-29.1.2.tgz (Root Library)
- jest-runtime-29.1.2.tgz
- glob-7.1.6.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
-
terser-webpack-plugin-4.2.3.tgz (Root Library)
- cacache-15.0.5.tgz
- glob-7.1.6.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
-
react-dev-utils-12.0.1.tgz (Root Library)
- fork-ts-checker-webpack-plugin-6.5.2.tgz
- glob-7.1.6.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
-
jest-26.6.0.tgz (Root Library)
- core-26.6.3.tgz
- jest-config-26.6.3.tgz
- glob-7.1.6.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
-
webpack-dev-server-4.9.0.tgz (Root Library)
- spdy-4.0.2.tgz
- spdy-transport-3.0.0.tgz
- hpack.js-2.1.6.tgz
- readable-stream-2.3.7.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
-
express-4.17.1.tgz (Root Library)
- send-0.17.1.tgz
- http-errors-1.7.3.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
-
jest-dom-5.11.9.tgz (Root Library)
- css-3.0.0.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
-
jest-circus-26.6.0.tgz (Root Library)
- jest-runtime-26.6.3.tgz
- glob-7.1.6.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
-
resolve-url-loader-3.1.4.tgz (Root Library)
- rework-1.0.1.tgz
- css-2.2.4.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
-
jest-dom-5.11.6.tgz (Root Library)
- css-3.0.0.tgz
- ❌ inherits-2.0.4.tgz (Vulnerable Library)
Vulnerability Details
Created automatically by the test suite
Publish Date: Jun 07, 2010 05:12 PM
URL: CVE-289561-266276
Threat Assessment
Exploit Maturity:N/A
EPSS:N/A
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin:
Release Date:
Fix Resolution :
🔴CVE-2022-3517
Vulnerable Library - minimatch-3.0.4.tgz
a glob matcher in javascript
Library home page: https://registry.npmjs.org/minimatch/-/minimatch-3.0.4.tgz
Dependency Hierarchy:
-
workbox-webpack-plugin-6.5.3.tgz (Root Library)
- workbox-build-6.5.3.tgz
- rollup-plugin-off-main-thread-2.2.3.tgz
- ejs-3.1.8.tgz
- jake-10.8.5.tgz
- ❌ minimatch-3.0.4.tgz (Vulnerable Library)
-
jest-circus-29.1.2.tgz (Root Library)
- jest-runtime-29.1.2.tgz
- glob-7.1.6.tgz
- ❌ minimatch-3.0.4.tgz (Vulnerable Library)
-
eslint-7.22.0.tgz (Root Library)
- eslintrc-0.4.0.tgz
- ❌ minimatch-3.0.4.tgz (Vulnerable Library)
-
terser-webpack-plugin-4.2.3.tgz (Root Library)
- cacache-15.0.5.tgz
- glob-7.1.6.tgz
- ❌ minimatch-3.0.4.tgz (Vulnerable Library)
-
react-dev-utils-12.0.1.tgz (Root Library)
- recursive-readdir-2.2.2.tgz
- ❌ minimatch-3.0.4.tgz (Vulnerable Library)
-
jest-26.6.0.tgz (Root Library)
- core-26.6.3.tgz
- jest-config-26.6.3.tgz
- glob-7.1.6.tgz
- ❌ minimatch-3.0.4.tgz (Vulnerable Library)
-
eslint-plugin-import-2.22.1.tgz (Root Library)
- ❌ minimatch-3.0.4.tgz (Vulnerable Library)
-
eslint-7.14.0.tgz (Root Library)
- eslintrc-0.2.1.tgz
- ❌ minimatch-3.0.4.tgz (Vulnerable Library)
-
jest-circus-26.6.0.tgz (Root Library)
- jest-runtime-26.6.3.tgz
- glob-7.1.6.tgz
- ❌ minimatch-3.0.4.tgz (Vulnerable Library)
-
babel-jest-26.6.3.tgz (Root Library)
- babel-plugin-istanbul-6.0.0.tgz
- test-exclude-6.0.0.tgz
- ❌ minimatch-3.0.4.tgz (Vulnerable Library)
Reachability Analysis
This vulnerability is potentially reachable:
Vulnerability Details
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
Publish Date: Oct 17, 2022 12:00 AM
URL: CVE-2022-3517
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: GHSA-f8q6-p94x-37v3
Release Date: Oct 17, 2022 12:00 AM
Fix Resolution : minimatch - 3.0.5
📂 Vulnerable Library - terser-webpack-plugin-4.2.3.tgz
Terser plugin for webpack
Findings
Details
🟣CVE-289561-266276
Vulnerable Library - inherits-2.0.4.tgz
Browser-friendly inheritance fully compatible with standard node.js inherits()
Library home page: https://registry.npmjs.org/inherits/-/inherits-2.0.4.tgz
Dependency Hierarchy:
mongoose-5.13.14.tgz (Root Library)
jest-circus-29.1.2.tgz (Root Library)
terser-webpack-plugin-4.2.3.tgz (Root Library)
react-dev-utils-12.0.1.tgz (Root Library)
jest-26.6.0.tgz (Root Library)
webpack-dev-server-4.9.0.tgz (Root Library)
express-4.17.1.tgz (Root Library)
jest-dom-5.11.9.tgz (Root Library)
jest-circus-26.6.0.tgz (Root Library)
resolve-url-loader-3.1.4.tgz (Root Library)
jest-dom-5.11.6.tgz (Root Library)
Vulnerability Details
Created automatically by the test suite
Publish Date: Jun 07, 2010 05:12 PM
URL: CVE-289561-266276
Threat Assessment
Exploit Maturity:N/A
EPSS:N/A
Score: 9.8
Suggested Fix
Type: Upgrade version
Origin:
Release Date:
Fix Resolution :
🔴CVE-2022-3517
Vulnerable Library - minimatch-3.0.4.tgz
a glob matcher in javascript
Library home page: https://registry.npmjs.org/minimatch/-/minimatch-3.0.4.tgz
Dependency Hierarchy:
workbox-webpack-plugin-6.5.3.tgz (Root Library)
jest-circus-29.1.2.tgz (Root Library)
eslint-7.22.0.tgz (Root Library)
terser-webpack-plugin-4.2.3.tgz (Root Library)
react-dev-utils-12.0.1.tgz (Root Library)
jest-26.6.0.tgz (Root Library)
eslint-plugin-import-2.22.1.tgz (Root Library)
eslint-7.14.0.tgz (Root Library)
jest-circus-26.6.0.tgz (Root Library)
babel-jest-26.6.3.tgz (Root Library)
Reachability Analysis
This vulnerability is potentially reachable:
Vulnerability Details
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
Publish Date: Oct 17, 2022 12:00 AM
URL: CVE-2022-3517
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: GHSA-f8q6-p94x-37v3
Release Date: Oct 17, 2022 12:00 AM
Fix Resolution : minimatch - 3.0.5