This repository was archived by the owner on Jan 19, 2023. It is now read-only.
This repository was archived by the owner on Jan 19, 2023. It is now read-only.
Bug: node-canvas
Incorrect vulnerability details #326
Open
Description
Vulnerability URL
https://ossindex.sonatype.org/vulnerability/sonatype-2019-0142
Description
pkg:npm/[email protected] - 1 vulnerability found!
Vulnerability Title: 1 vulnerability found
ID: sonatype-2019-0142
Description: 1 non-CVE vulnerability found. To see more details, please create a free account at https://ossindex.sonatype.org/ and request for this information using your registered account
CVSS Score: 8.6
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Reference: https://ossindex.sonatype.org/vulnerability/sonatype-2019-0142
however, this vulnerability was fixed long time ago - it clearly states that it only impacts versions 1.6.9 and below and here vulnerability is reported for version 2.10.0!
see for fix confirmation GHSA-vpq5-4rc8-c222
this seems to be a NEW false-positive as it was not reported for recent versions, so there may be a semver compare mismatch on ossindex side?