-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
Description
WS-2017-0330 - Medium Severity Vulnerability
Vulnerable Library - mime-1.3.4.tgz
A comprehensive library for mime-type mapping
Library home page: https://registry.npmjs.org/mime/-/mime-1.3.4.tgz
Path to dependency file: /NodeServer/package.json
Path to vulnerable library: /tmp/git/NodeServer/node_modules/mime/package.json
Dependency Hierarchy:
- express-4.13.3.tgz (Root Library)
- send-0.13.0.tgz
- ❌ mime-1.3.4.tgz (Vulnerable Library)
- send-0.13.0.tgz
Found in HEAD commit: fa133e03329a64397844c4874edcc1e40f443ebd
Vulnerability Details
Affected version of mime (1.0.0 throw 1.4.0 and 2.0.0 throw 2.0.2), are vulnerable to regular expression denial of service.
Publish Date: 2017-09-27
URL: WS-2017-0330
Suggested Fix
Type: Upgrade version
Origin: broofa/mime@1df903f
Release Date: 2019-04-03
Fix Resolution: 1.4.1,2.0.3
Step up your Open Source Security Game with WhiteSource here
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource