axios icon indicating copy to clipboard operation
axios copied to clipboard

WS-2018-0107 (High) detected in open-0.0.5.tgz

Open mend-bolt-for-github[bot] opened this issue 3 years ago • 2 comments

WS-2018-0107 - High Severity Vulnerability

Vulnerable Library - open-0.0.5.tgz

open a file or url in the user's preferred application

Library home page: https://registry.npmjs.org/open/-/open-0.0.5.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/open/package.json

Dependency Hierarchy:

  • webpack-dev-server-1.16.5.tgz (Root Library)
    • :x: open-0.0.5.tgz (Vulnerable Library)

Found in HEAD commit: 91ceb6046aaa22e9934ed13ea5acba9c988c490c

Found in base branch: master

Vulnerability Details

All versions of open are vulnerable to command injection when unsanitized user input is passed in.

Publish Date: 2018-05-16

URL: WS-2018-0107

CVSS 3 Score Details (7.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.mend.io/vulnerability-database/WS-2018-0107

Release Date: 2018-01-27

Fix Resolution (open): 6.0.0

Direct dependency fix Resolution (webpack-dev-server): 2.2.0


Step up your Open Source Security Game with Mend here