@carbon/ibmdotcom-services-store-1.53.3.tgz: 2 vulnerabilities (highest severity is: 7.5) - autoclosed #12104
Labels
Mend: dependency security vulnerability
Security vulnerability detected by Mend
Vulnerable Library - @carbon/ibmdotcom-services-store-1.53.3.tgz
Path to dependency file: /package.json
Path to vulnerable library: /.yarn/cache/axios-npm-0.27.2-dbe3a48aea-2efaf18dd0.zip
Found in HEAD commit: f49c073f0f0b156fb1d6d5f6075fc0f1d348fb6d
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
WS-2023-0439
Vulnerable Library - axios-0.27.2.tgz
Promise based HTTP client for the browser and node.js
Library home page: https://registry.npmjs.org/axios/-/axios-0.27.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /.yarn/cache/axios-npm-0.27.2-dbe3a48aea-2efaf18dd0.zip
Dependency Hierarchy:
Found in HEAD commit: f49c073f0f0b156fb1d6d5f6075fc0f1d348fb6d
Found in base branch: main
Vulnerability Details
Axios is vulnerable to Regular Expression Denial of Service (ReDoS). When a manipulated string is provided as input to the format method, the regular expression exhibits a time complexity of O(n^2). Server becomes unable to provide normal service due to the excessive cost and time wasted in processing vulnerable regular expressions.
Publish Date: 2023-10-25
URL: WS-2023-0439
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/WS-2023-0439
Release Date: 2023-10-25
Fix Resolution: axios - 1.6.3,0.20.0
CVE-2023-45857
Vulnerable Library - axios-0.27.2.tgz
Promise based HTTP client for the browser and node.js
Library home page: https://registry.npmjs.org/axios/-/axios-0.27.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /.yarn/cache/axios-npm-0.27.2-dbe3a48aea-2efaf18dd0.zip
Dependency Hierarchy:
Found in HEAD commit: f49c073f0f0b156fb1d6d5f6075fc0f1d348fb6d
Found in base branch: main
Vulnerability Details
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
Publish Date: 2023-11-08
URL: CVE-2023-45857
CVSS 3 Score Details (6.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: axios/axios#6006
Release Date: 2023-11-08
Fix Resolution: axios - 1.6.0
The text was updated successfully, but these errors were encountered: