WS-2019-0425 (Medium) detected in mochav4.1.0, juice-shopjuice-shop-8.3.0_node11_linux_x64 - autoclosed #102
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
WS-2019-0425 - Medium Severity Vulnerability
Vulnerable Libraries - mochav4.1.0, juice-shopjuice-shop-8.3.0_node11_linux_x64
Vulnerability Details
Mocha is vulnerable to ReDoS attack. If the stack trace in utils.js begins with a large error message, and full-trace is not enabled, utils.stackTraceFilter() will take exponential run time.
Publish Date: 2019-01-24
URL: WS-2019-0425
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: v6.0.0
Release Date: 2020-05-07
Fix Resolution: https://github.com/mochajs/mocha/commit/1a43d8b11a64e4e85fe2a61aed91c259bbbac559
The text was updated successfully, but these errors were encountered: