WS-2017-0236 - Medium Severity Vulnerability
Vulnerable Library - growl-1.8.1.tgz
Growl unobtrusive notifications
path: /tmp/git/flummox/node_modules/growl/package.json
Library home page: http://registry.npmjs.org/growl/-/growl-1.8.1.tgz
Dependency Hierarchy:
- mocha-2.2.1.tgz (Root Library)
- ❌ growl-1.8.1.tgz (Vulnerable Library)
Vulnerability Details
Affected versions of the package are vulnerable to Arbitrary Code Injection.
Publish Date: 2017-05-01
URL: WS-2017-0236
CVSS 2 Score Details (5.6)
Base Score Metrics not available
Suggested Fix
Type: Change files
Origin: tj/node-growl@d9f6ea2
Release Date: 2016-09-05
Fix Resolution: Replace or update the following files: package.json, growl.js
Step up your Open Source Security Game with WhiteSource here
WS-2017-0236 - Medium Severity Vulnerability
Growl unobtrusive notifications
path: /tmp/git/flummox/node_modules/growl/package.json
Library home page: http://registry.npmjs.org/growl/-/growl-1.8.1.tgz
Dependency Hierarchy:
Affected versions of the package are vulnerable to Arbitrary Code Injection.
Publish Date: 2017-05-01
URL: WS-2017-0236
Base Score Metrics not available
Type: Change files
Origin: tj/node-growl@d9f6ea2
Release Date: 2016-09-05
Fix Resolution: Replace or update the following files: package.json, growl.js
Step up your Open Source Security Game with WhiteSource here