Skip to content
This repository was archived by the owner on Jan 19, 2023. It is now read-only.
This repository was archived by the owner on Jan 19, 2023. It is now read-only.

Bug: node-canvas Incorrect vulnerability details #326

Open
@vladmandic

Description

@vladmandic

Vulnerability URL
https://ossindex.sonatype.org/vulnerability/sonatype-2019-0142

Description

pkg:npm/[email protected] - 1 vulnerability found!

  Vulnerability Title:  1 vulnerability found
  ID:  sonatype-2019-0142
  Description:  1 non-CVE vulnerability found. To see more details, please create a free account at https://ossindex.sonatype.org/ and request for this information using your registered account
  CVSS Score:  8.6
  CVSS Vector:  CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
  Reference:  https://ossindex.sonatype.org/vulnerability/sonatype-2019-0142

however, this vulnerability was fixed long time ago - it clearly states that it only impacts versions 1.6.9 and below and here vulnerability is reported for version 2.10.0!

see for fix confirmation GHSA-vpq5-4rc8-c222

this seems to be a NEW false-positive as it was not reported for recent versions, so there may be a semver compare mismatch on ossindex side?

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions