WS-2017-3757 (Medium) detected in content-type-parser-1.0.1.tgz, content-type-parser-1.0.2.tgz - autoclosed #106
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
WS-2017-3757 - Medium Severity Vulnerability
Vulnerable Libraries - content-type-parser-1.0.1.tgz, content-type-parser-1.0.2.tgz
content-type-parser-1.0.1.tgz
Parse the value of the Content-Type header
Library home page: https://registry.npmjs.org/content-type-parser/-/content-type-parser-1.0.1.tgz
Path to dependency file: /npm_and_yarn/spec/fixtures/projects/yarn/no_lockfile_change/package.json
Path to vulnerable library: /npm_and_yarn/spec/fixtures/projects/yarn/no_lockfile_change/node_modules/content-type-parser
Dependency Hierarchy:
content-type-parser-1.0.2.tgz
Parse the value of the Content-Type header
Library home page: https://registry.npmjs.org/content-type-parser/-/content-type-parser-1.0.2.tgz
Path to dependency file: /npm_and_yarn/spec/fixtures/projects/yarn/lockfile_only_change/package.json
Path to vulnerable library: /npm_and_yarn/spec/fixtures/projects/yarn/lockfile_only_change/node_modules/content-type-parser
Dependency Hierarchy:
Found in HEAD commit: ba8cd9078c8ce0cb202767d627706711237abf71
Found in base branch: main
Vulnerability Details
all versions prior to 2.0.0 of content-type-parser npm package are vulnerable to ReDoS via the user agent parser. the vulnerability was fixed by reintroducing a new parser and deleting the old one.
Publish Date: 2017-12-10
URL: WS-2017-3757
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2017-12-10
Fix Resolution: v2.0.0
The text was updated successfully, but these errors were encountered: