Update dependency body-parser to v1.19.0 #25
Dev - Mend for GitHub.com / Mend Security Check
failed
May 31, 2024 in 3m 33s
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 2 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2022-24999Path to dependency file: /package.json Path to vulnerable library: /node_modules/express/node_modules/qs/package.json Dependency Hierarchy: -> express-4.15.5.tgz (Root Library) -> ❌ qs-6.5.0.tgz (Vulnerable Library) |
High | 7.5 | qs-6.5.0.tgz | Upgrade to version: qs - 6.2.4,6.3.3,6.4.1,6.5.3,6.6.1,6.7.3,6.8.3,6.9.7,6.10.3 | #4 |
CVE-2022-24999Path to dependency file: /package.json Path to vulnerable library: /node_modules/qs/package.json Dependency Hierarchy: -> body-parser-1.19.0.tgz (Root Library) -> ❌ qs-6.7.0.tgz (Vulnerable Library) |
High | 7.5 | qs-6.7.0.tgz | Upgrade to version: qs - 6.2.4,6.3.3,6.4.1,6.5.3,6.6.1,6.7.3,6.8.3,6.9.7,6.10.3 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2022-24999 | qs-6.5.1.tgz |
Base branch total remaining vulnerabilities: 6
Base branch commit: null
Total libraries scanned: 287
Scan token: 0363310ad23a422fbca7fe40de3ff2d7
Loading