Skip to content
This repository has been archived by the owner on Feb 8, 2024. It is now read-only.

CVE-2022-48345 (Medium) detected in sanitize-url-6.0.0.tgz #507

Closed
mend-for-github-com bot opened this issue Feb 24, 2023 · 1 comment
Closed

CVE-2022-48345 (Medium) detected in sanitize-url-6.0.0.tgz #507

mend-for-github-com bot opened this issue Feb 24, 2023 · 1 comment
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-for-github-com
Copy link

mend-for-github-com bot commented Feb 24, 2023

CVE-2022-48345 - Medium Severity Vulnerability

Vulnerable Library - sanitize-url-6.0.0.tgz

A url sanitizer

Library home page: https://registry.npmjs.org/@braintree/sanitize-url/-/sanitize-url-6.0.0.tgz

Path to dependency file: /src/pybind/mgr/dashboard/frontend/package.json

Path to vulnerable library: /src/pybind/mgr/dashboard/frontend/node_modules/@braintree/sanitize-url/package.json

Dependency Hierarchy:

  • swagger-ui-4.12.0.tgz (Root Library)
    • sanitize-url-6.0.0.tgz (Vulnerable Library)

Found in HEAD commit: aa78617d024ccd26801e43c6980f939cf8bded5f

Found in base branch: main

Vulnerability Details

sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.

Publish Date: 2023-02-24

URL: CVE-2022-48345

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2023-02-24

Fix Resolution (@braintree/sanitize-url): 6.0.1

Direct dependency fix Resolution (swagger-ui): 4.13.0


⛑️ Automatic Remediation will be attempted for this issue.

@mend-for-github-com mend-for-github-com bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Feb 24, 2023
@shailesh-vaidya
Copy link

Closing as an obsolete

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

1 participant