Vulnerable Libraries - semver-7.0.0.tgz, semver-5.3.0.tgz, semver-7.3.8.tgz, semver-7.3.7.tgz, semver-6.3.0.tgz, semver-5.7.0.tgz, semver-5.7.1.tgz, semver-4.3.6.tgz, semver-5.5.1.tgz
semver-7.0.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-7.0.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
semver-5.3.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.3.0.tgz
Path to dependency file: /script/vsts/package.json
Path to vulnerable library: /script/vsts/node_modules/semver/package.json,/script/node_modules/semver/package.json
Dependency Hierarchy:
- ❌ semver-5.3.0.tgz (Vulnerable Library)
semver-7.3.8.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-7.3.8.tgz
Path to dependency file: /script/package.json
Path to vulnerable library: /script/node_modules/global-agent/node_modules/semver/package.json,/script/node_modules/electron-packager/node_modules/semver/package.json
Dependency Hierarchy:
- electron-packager-16.0.0.tgz (Root Library)
- ❌ semver-7.3.8.tgz (Vulnerable Library)
semver-7.3.7.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-7.3.7.tgz
Dependency Hierarchy:
- npm-8.19.2.tgz (Root Library)
- ❌ semver-7.3.7.tgz (Vulnerable Library)
semver-6.3.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-6.3.0.tgz
Path to dependency file: /script/package.json
Path to vulnerable library: /script/node_modules/@electron/get/node_modules/semver/package.json
Dependency Hierarchy:
- electron-packager-16.0.0.tgz (Root Library)
- get-2.0.1.tgz
- ❌ semver-6.3.0.tgz (Vulnerable Library)
semver-5.7.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.7.0.tgz
Path to dependency file: /script/package.json
Path to vulnerable library: /script/node_modules/cross-spawn/node_modules/semver/package.json,/script/node_modules/eslint/node_modules/semver/package.json
Dependency Hierarchy:
- eslint-5.16.0.tgz (Root Library)
- ❌ semver-5.7.0.tgz (Vulnerable Library)
semver-5.7.1.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.7.1.tgz
Dependency Hierarchy:
- fs-admin-0.19.0.tgz (Root Library)
- prebuild-install-6.1.3.tgz
- node-abi-2.30.0.tgz
- ❌ semver-5.7.1.tgz (Vulnerable Library)
semver-4.3.6.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-4.3.6.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json,/script/node_modules/read-package-json/node_modules/semver/package.json,/script/node_modules/read-installed/node_modules/semver/package.json
Dependency Hierarchy:
- ❌ semver-4.3.6.tgz (Vulnerable Library)
semver-5.5.1.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.5.1.tgz
Path to dependency file: /packages/about/package.json
Path to vulnerable library: /packages/about/package.json
Dependency Hierarchy:
- ❌ semver-5.5.1.tgz (Vulnerable Library)
Found in HEAD commit: 808ed16784ca49c0e5810becefba198982d2916e
Found in base branch: electron-upgrade
CVE-2022-25883 - High Severity Vulnerability
semver-7.0.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-7.0.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
semver-5.3.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.3.0.tgz
Path to dependency file: /script/vsts/package.json
Path to vulnerable library: /script/vsts/node_modules/semver/package.json,/script/node_modules/semver/package.json
Dependency Hierarchy:
semver-7.3.8.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-7.3.8.tgz
Path to dependency file: /script/package.json
Path to vulnerable library: /script/node_modules/global-agent/node_modules/semver/package.json,/script/node_modules/electron-packager/node_modules/semver/package.json
Dependency Hierarchy:
semver-7.3.7.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-7.3.7.tgz
Dependency Hierarchy:
semver-6.3.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-6.3.0.tgz
Path to dependency file: /script/package.json
Path to vulnerable library: /script/node_modules/@electron/get/node_modules/semver/package.json
Dependency Hierarchy:
semver-5.7.0.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.7.0.tgz
Path to dependency file: /script/package.json
Path to vulnerable library: /script/node_modules/cross-spawn/node_modules/semver/package.json,/script/node_modules/eslint/node_modules/semver/package.json
Dependency Hierarchy:
semver-5.7.1.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.7.1.tgz
Dependency Hierarchy:
semver-4.3.6.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-4.3.6.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json,/script/node_modules/read-package-json/node_modules/semver/package.json,/script/node_modules/read-installed/node_modules/semver/package.json
Dependency Hierarchy:
semver-5.5.1.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.5.1.tgz
Path to dependency file: /packages/about/package.json
Path to vulnerable library: /packages/about/package.json
Dependency Hierarchy:
Found in HEAD commit: 808ed16784ca49c0e5810becefba198982d2916e
Found in base branch: electron-upgrade
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
Publish Date: 2023-06-21
URL: CVE-2022-25883
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: GHSA-c2qf-rxjj-qqgw
Release Date: 2023-06-21
Fix Resolution (semver): 7.5.2
Direct dependency fix Resolution (eslint): 6.0.0
Step up your Open Source Security Game with Mend here