This repository has been archived by the owner on Sep 22, 2021. It is now read-only.
WS-2017-0236 (Medium) detected in growl-1.9.2.tgz #9
Labels
security vulnerability
Security vulnerability detected by WhiteSource
WS-2017-0236 - Medium Severity Vulnerability
Vulnerable Library - growl-1.9.2.tgz
Growl unobtrusive notifications
Library home page: https://registry.npmjs.org/growl/-/growl-1.9.2.tgz
Path to dependency file: /tmp/ws-scm/oas-nodegen/package.json
Path to vulnerable library: /tmp/ws-scm/oas-nodegen/node_modules/growl/package.json
Dependency Hierarchy:
Found in HEAD commit: 68d751bdae4e5002c9a62b3c3b3e2371120cff95
Vulnerability Details
Affected versions of the package are vulnerable to Arbitrary Code Injection.
Publish Date: 2016-09-05
URL: WS-2017-0236
CVSS 2 Score Details (5.6)
Base Score Metrics not available
Suggested Fix
Type: Change files
Origin: tj/node-growl@d9f6ea2
Release Date: 2016-09-05
Fix Resolution: Replace or update the following files: package.json, growl.js
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: