WS-2017-3757 (Medium) detected in content-type-parser-1.0.2.tgz, content-type-parser-1.0.1.tgz #24
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
WS-2017-3757 - Medium Severity Vulnerability
Vulnerable Libraries - content-type-parser-1.0.2.tgz, content-type-parser-1.0.1.tgz
content-type-parser-1.0.2.tgz
Parse the value of the Content-Type header
Library home page: https://registry.npmjs.org/content-type-parser/-/content-type-parser-1.0.2.tgz
Path to dependency file: /fixtures/concurrent/time-slicing/package.json
Path to vulnerable library: /fixtures/concurrent/time-slicing/package.json,/fixtures/expiration/package.json
Dependency Hierarchy:
content-type-parser-1.0.1.tgz
Parse the value of the Content-Type header
Library home page: https://registry.npmjs.org/content-type-parser/-/content-type-parser-1.0.1.tgz
Path to dependency file: /fixtures/attribute-behavior/package.json
Path to vulnerable library: /fixtures/attribute-behavior/package.json,/fixtures/ssr/package.json,/fixtures/fiber-debugger/package.json,/fixtures/dom/package.json
Dependency Hierarchy:
Found in HEAD commit: c546697344431dcd6c04b4fea877c488ef3a6ad5
Found in base branch: main
Vulnerability Details
all versions prior to 2.0.0 of content-type-parser npm package are vulnerable to ReDoS via the user agent parser. the vulnerability was fixed by reintroducing a new parser and deleting the old one.
Publish Date: 2017-12-10
URL: WS-2017-3757
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2017-12-10
Fix Resolution: v2.0.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: