CVE-2020-7753 (High) detected in trim-0.0.1.tgz
Opened this issue · 3 comments
CVE-2020-7753 - High Severity Vulnerability
Vulnerable Library - trim-0.0.1.tgz
Trim string whitespace
Library home page: https://registry.npmjs.org/trim/-/trim-0.0.1.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/trim/package.json
Dependency Hierarchy:
- render-content-5.2.1.tgz (Root Library)
- hubdown-2.6.0.tgz
- remark-parse-7.0.2.tgz
- ❌ trim-0.0.1.tgz (Vulnerable Library)
- remark-parse-7.0.2.tgz
- hubdown-2.6.0.tgz
Found in HEAD commit: 4e6b7ecb9b39fc7d86c420ddb87c5c3712578339
Found in base branch: main
Vulnerability Details
All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().
Publish Date: 2020-10-27
URL: CVE-2020-7753
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Step up your Open Source Security Game with Mend here
✔️ This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.
ℹ️ This issue was automatically re-opened by WhiteSource because the vulnerable library in the specific branch(es) has been detected in the WhiteSource inventory.
ℹ️ This issue was automatically re-opened by WhiteSource because the vulnerable library in the specific branch(es) has been detected in the WhiteSource inventory.