Update dependency body-parser to v1.19.0 #9
Mend for GitHub.com / WhiteSource Security Check
failed
Jan 2, 2024 in 48s
Security Report
You have successfully remediated 6 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2022-24999Path to dependency file: /package.json Path to vulnerable library: /node_modules/body-parser/node_modules/qs/package.json Dependency Hierarchy: -> body-parser-1.19.0.tgz (Root Library) -> ❌ qs-6.7.0.tgz (Vulnerable Library) |
High | 7.5 | qs-6.7.0.tgz | Upgrade to version: qs - 6.2.4,6.3.3,6.4.1,6.5.3,6.6.1,6.7.3,6.8.3,6.9.7,6.10.3 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2022-23540 | jsonwebtoken-8.4.0.tgz |
CVE-2022-23541 | jsonwebtoken-8.4.0.tgz |
CVE-2021-3918 | json-schema-0.2.3.tgz |
CVE-2022-23539 | jsonwebtoken-8.4.0.tgz |
CVE-2022-38900 | decode-uri-component-0.2.0.tgz |
CVE-2020-15366 | ajv-6.7.0.tgz |
Base branch total remaining vulnerabilities: 9
Base branch commit: null
Total libraries scanned: 126
Scan token: dc0b14c97338427b8ea5b5ef366e3bc1
Loading