This repository was archived by the owner on Jul 13, 2021. It is now read-only.
CVE-2017-16138 (High) detected in mime-1.2.11.tgz #59
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2017-16138 - High Severity Vulnerability
A comprehensive library for mime-type mapping
Library home page: https://registry.npmjs.org/mime/-/mime-1.2.11.tgz
Path to dependency file: curratelo/package.json
Path to vulnerable library: curratelo/node_modules/feedparser/node_modules/mime/package.json
Dependency Hierarchy:
The mime module < 1.4.1, 2.0.1, 2.0.2 is vulnerable to regular expression denial of service when a mime lookup is performed on untrusted user input.
Publish Date: 2018-06-07
URL: CVE-2017-16138
Base Score Metrics:
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16138
Release Date: 2018-06-07
Fix Resolution: 1.4.1,2.0.3
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: