You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
broofa/node-mime v1.4.1 is referenced by pillarjs/send v0.16.2, which in turn is referenced by expressjs/express v4.16.4.
pillarjs/send upgraded broofa/node-mime to v1.6.0, which was merged by pillarjs/send#154 about 6 weeks ago.
So this appears to be resolved, but is currently waiting on expressjs/express to get an upgraded pillarjs/send version that has this update. Once that happens, I can update this project.
CVE-2017-16138 - High Severity Vulnerability
Vulnerable Library - mime-1.4.1.tgz
A comprehensive library for mime-type mapping
path: /otl-bot/node_modules/mime/package.json
Library home page: https://registry.npmjs.org/mime/-/mime-1.4.1.tgz
Dependency Hierarchy:
Found in HEAD commit: d9cc3559ea46f65cd828d87f859940dec3901d21
Vulnerability Details
The mime module is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
Publish Date: 2018-06-07
URL: CVE-2017-16138
CVSS 3 Score Details (7.5)
Base Score Metrics:
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: