You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property proto, which is recursively assigned to all the objects in the program.
✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
mend-bolt-for-githubbot
changed the title
eslint-0.97.0.tgz: 1 vulnerabilities (highest severity is: 8.2)
eslint-0.97.0.tgz: 1 vulnerabilities (highest severity is: 8.2) - autoclosed
Dec 18, 2024
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Found in HEAD commit: 14d2f2fee1365598f76cf1e2e44ce7c0251a861c
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - dset-3.1.3.tgz
Library home page: https://registry.npmjs.org/dset/-/dset-3.1.3.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
Found in HEAD commit: 14d2f2fee1365598f76cf1e2e44ce7c0251a861c
Found in base branch: main
Vulnerability Details
Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property proto, which is recursively assigned to all the objects in the program.
Publish Date: 2024-09-11
URL: CVE-2024-21529
CVSS 3 Score Details (8.2)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2024-21529
Release Date: 2024-09-11
Fix Resolution (dset): 3.1.4
Direct dependency fix Resolution (@storm-software/eslint): 0.97.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: