This repository has been archived by the owner on Jun 27, 2022. It is now read-only.
WS-2017-3757 (Medium) detected in content-type-parser-1.0.2.tgz - autoclosed #45
Labels
security vulnerability
Security vulnerability detected by WhiteSource
WS-2017-3757 - Medium Severity Vulnerability
Vulnerable Library - content-type-parser-1.0.2.tgz
Parse the value of the Content-Type header
Library home page: https://registry.npmjs.org/content-type-parser/-/content-type-parser-1.0.2.tgz
Path to dependency file: react-playground/package.json
Path to vulnerable library: react-playground/node_modules/content-type-parser/package.json
Dependency Hierarchy:
Found in HEAD commit: 1e308b7392b9b3b708488b10efeda90527d0aa12
Found in base branch: master
Vulnerability Details
all versions prior to 2.0.0 of content-type-parser npm package are vulnerable to ReDoS via the user agent parser. the vulnerability was fixed by reintroducing a new parser and deleting the old one.
Publish Date: 2017-12-10
URL: WS-2017-3757
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: jsdom/whatwg-mimetype#3
Release Date: 2020-04-30
Fix Resolution: v2.0.0
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: