JSHint icon indicating copy to clipboard operation
JSHint copied to clipboard

WS-2018-0148 Low Severity Vulnerability detected by WhiteSource

Open mend-bolt-for-github[bot] opened this issue 6 years ago • 0 comments

WS-2018-0148 - Low Severity Vulnerability

Vulnerable Library - utile-0.2.1.tgz

A drop-in replacement for `util` with some additional advantageous functions

path: /tmp/git/JSHint/node_modules/jshint/node_modules/utile/package.json

Library home page: http://registry.npmjs.org/utile/-/utile-0.2.1.tgz

Dependency Hierarchy:

  • jscs-1.11.3.tgz (Root Library)
    • prompt-0.2.14.tgz
      • :x: utile-0.2.1.tgz (Vulnerable Library)

Vulnerability Details

utile allocates uninitialized Buffers when number is passed in input. Before version 0.3.0

Publish Date: 2018-07-16

URL: WS-2018-0148

CVSS 2 Score Details (1.8)

Base Score Metrics not available


Step up your Open Source Security Game with WhiteSource here