Update dependency express to ^4.21.2 #11
Open
Mend for GitHub.com / Mend Security Check
failed
Dec 7, 2024 in 6m 42s
Security Report
You have successfully remediated 6 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-47764Path to dependency file: /package.json Path to vulnerable library: /node_modules/engine.io/node_modules/cookie/package.json Dependency Hierarchy: -> socket.io-3.1.2.tgz (Root Library) -> engine.io-4.1.2.tgz -> ❌ cookie-0.4.2.tgz (Vulnerable Library) |
Medium | 5.3 | cookie-0.4.2.tgz | Upgrade to version: cookie - 0.7.0 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-45590 | body-parser-1.20.2.tgz |
CVE-2024-47764 | cookie-0.6.0.tgz |
CVE-2024-4067 | micromatch-4.0.7.tgz |
CVE-2024-45296 | path-to-regexp-0.1.7.tgz |
CVE-2024-47764 | cookie-0.4.1.tgz |
CVE-2024-52798 | path-to-regexp-0.1.7.tgz |
Base branch total remaining vulnerabilities: 64
Base branch commit: 0c596b0a070fe031592d3b120f9481a74f2b6e16
Total libraries scanned: 996
Scan token: 03fc8231ea4f4918b9a43123d978bd9a
Loading