This repository has been archived by the owner on Dec 13, 2023. It is now read-only.
CVE-2021-23406 (High) detected in degenerator-1.0.4.tgz #48
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2021-23406 - High Severity Vulnerability
Vulnerable Library - degenerator-1.0.4.tgz
Turns sync functions into async generator functions
Library home page: https://registry.npmjs.org/degenerator/-/degenerator-1.0.4.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/degenerator/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. NOTE: The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.
Publish Date: 2021-08-24
URL: CVE-2021-23406
CVSS 3 Score Details (9.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-9j49-mfvp-vmhm
Release Date: 2021-08-24
Fix Resolution: pac-resolver -5.0.0, degenerator - 3.0.1
The text was updated successfully, but these errors were encountered: