Skip to content

CVE-2022-38900 @ Npm-decode-uri-component-0.2.2 #179

@westonphillips

Description

@westonphillips

Vulnerable Package issue exists @ Npm-decode-uri-component-0.2.2 in branch main

decode-uri-component is vulnerable to Improper Input Validation resulting in DoS.

Namespace: westonphillips
Repository: CheckmarxOnePOV
Repository Url: https://github.com/westonphillips/CheckmarxOnePOV
CxAST-Project: westonphillips/CheckmarxOnePOV
CxAST platform scan: 6a8170d0-38fa-4efc-81df-42628474102c
Branch: main
Application: CheckmarxOnePOV
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-20


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: HIGH
Remediation Upgrade Recommendation: 0.3.0


References
Advisory
Issue
Vulnerable code

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions