-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
Description
WS-2017-0247 - Low Severity Vulnerability
Vulnerable Libraries - ms-0.7.2.tgz, ms-0.7.1.tgz
ms-0.7.2.tgz
Tiny milisecond conversion utility
path: /tmp/git/vulnerable-web-application/node_modules/ms/package.json
Library home page: https://registry.npmjs.org/ms/-/ms-0.7.2.tgz
Dependency Hierarchy:
- body-parser-1.16.1.tgz (Root Library)
- debug-2.6.1.tgz
- ❌ ms-0.7.2.tgz (Vulnerable Library)
- debug-2.6.1.tgz
ms-0.7.1.tgz
Tiny ms conversion utility
path: /tmp/git/vulnerable-web-application/node_modules/express/node_modules/ms/package.json
Library home page: http://registry.npmjs.org/ms/-/ms-0.7.1.tgz
Dependency Hierarchy:
- express-4.13.2.tgz (Root Library)
- debug-2.2.0.tgz
- ❌ ms-0.7.1.tgz (Vulnerable Library)
- debug-2.2.0.tgz
Vulnerability Details
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS).
Publish Date: 2017-05-15
URL: WS-2017-0247
Suggested Fix
Type: Change files
Origin: vercel/ms@305f2dd
Release Date: 2017-04-12
Fix Resolution: Replace or update the following file: index.js
Step up your Open Source Security Game with WhiteSource here
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource