This repository has been archived by the owner on Dec 14, 2022. It is now read-only.
CVE-2021-35065 (High) detected in glob-parent-5.1.1.tgz, glob-parent-2.0.0.tgz - autoclosed #77
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2021-35065 - High Severity Vulnerability
Vulnerable Libraries - glob-parent-5.1.1.tgz, glob-parent-2.0.0.tgz
glob-parent-5.1.1.tgz
Extract the non-magic parent path from a glob string.
Library home page: https://registry.npmjs.org/glob-parent/-/glob-parent-5.1.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/glob-parent
Dependency Hierarchy:
glob-parent-2.0.0.tgz
Strips glob magic from a string to provide the parent path
Library home page: https://registry.npmjs.org/glob-parent/-/glob-parent-2.0.0.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/glob-parent
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
The package glob-parent before 6.0.1 are vulnerable to Regular Expression Denial of Service (ReDoS)
Publish Date: 2021-06-22
URL: CVE-2021-35065
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-cj88-88mr-972w
Release Date: 2021-06-22
Fix Resolution (glob-parent): 6.0.1
Direct dependency fix Resolution (eslint): 8.0.0
The text was updated successfully, but these errors were encountered: