Lucene search

K
githubGitHub Advisory DatabaseGHSA-7FHM-MQM4-2WP7
HistoryMar 13, 2020 - 8:36 p.m.

Withdrawn: ESLint dependencies are vulnerable (ReDoS and Prototype Pollution)

2020-03-1320:36:16
GitHub Advisory Database
github.com
296

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

5.6 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

42.9%

Withdrawn
GitHub has withdrawn this advisory in place of GHSA-vh95-rmgr-6w4m and GHSA-6chw-6frg-f759.
The reason for withdrawing is that some mistakes were made during the ingestion of CVE-2020-7598
which caused this advisory to be published with incorrect information.

In order to provide accurate advisory information, new advisories were created:

Affected configurations

Vulners
Node
priorswoodacorn_commsRange<7.1.1android
OR
priorswoodacorn_commsRange<6.4.1android
OR
priorswoodacorn_commsRange<5.7.4android
OR
substackminimistRange<1.2.2node.js
CPENameOperatorVersion
acornlt7.1.1
acornlt6.4.1
acornlt5.7.4
minimistlt1.2.2

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

5.6 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

42.9%