This repository has been archived by the owner on Dec 28, 2021. It is now read-only.
CVE-2017-16116 (High) detected in multiple libraries #22
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2017-16116 - High Severity Vulnerability
Vulnerable Libraries - underscore.string-2.2.1.tgz, underscore.string-2.4.0.tgz, underscore.string-2.3.3.tgz
underscore.string-2.2.1.tgz
String manipulation extensions for Underscore.js javascript library.
Library home page: https://registry.npmjs.org/underscore.string/-/underscore.string-2.2.1.tgz
Path to dependency file: styles/package.json
Path to vulnerable library: styles/node_modules/underscore.string/package.json
Dependency Hierarchy:
underscore.string-2.4.0.tgz
String manipulation extensions for Underscore.js javascript library.
Library home page: https://registry.npmjs.org/underscore.string/-/underscore.string-2.4.0.tgz
Path to dependency file: styles/package.json
Path to vulnerable library: styles/node_modules/argparse/node_modules/underscore.string/package.json
Dependency Hierarchy:
underscore.string-2.3.3.tgz
String manipulation extensions for Underscore.js javascript library.
Library home page: https://registry.npmjs.org/underscore.string/-/underscore.string-2.3.3.tgz
Path to dependency file: styles/package.json
Path to vulnerable library: styles/node_modules/grunt-legacy-log-utils/node_modules/underscore.string/package.json,styles/node_modules/grunt-legacy-log/node_modules/underscore.string/package.json
Dependency Hierarchy:
Found in HEAD commit: caf024d40f859e2b99deb7992dd28b4511016657
Found in base branch: master
Vulnerability Details
The string module is a module that provides extra string operations. The string module is vulnerable to regular expression denial of service when specifically crafted untrusted user input is passed into the underscore or unescapeHTML methods.
Publish Date: 2018-06-07
URL: CVE-2017-16116
CVSS 3 Score Details (7.5)
Base Score Metrics:
The text was updated successfully, but these errors were encountered: