@kleros/kleros-v2-web-devtools-0.1.0.tgz: 1 vulnerabilities (highest severity is: 4.3) #1715
Labels
dependencies
Pull requests that update a dependency file
Mend: dependency security vulnerability
Security vulnerability detected by Mend
Type: Security🛡️
Custom label for issues opened by WhiteSource
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Found in HEAD commit: a3f5416a71e1112e0fb8a2d29dc240c8665c7335
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - nanoid-3.3.7.tgz
Library home page: https://registry.npmjs.org/nanoid/-/nanoid-3.3.7.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
Found in HEAD commit: a3f5416a71e1112e0fb8a2d29dc240c8665c7335
Found in base branches: dev, master
Vulnerability Details
nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
Publish Date: 2024-12-09
URL: CVE-2024-55565
CVSS 3 Score Details (4.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2024-55565
Release Date: 2024-12-09
Fix Resolution: nanoid - 3.3.8,5.0.9
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: