Update dependency traverse to ~0.6.10 #64
Mend/5034428 / Mend Security Check
failed
Oct 17, 2024 in 3m 39s
Security Report
The Security Check found 3 vulnerabilities.
CVE | Severity | CVSS Score | Exploit Maturity | EPSS | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|---|---|
CVE-2020-8203Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ lodash-4.17.13.tgz (Vulnerable Library) |
High | 7.4 | Not Defined | 1.7% | lodash-4.17.13.tgz | Upgrade to version: lodash - 4.17.19 | None |
CVE-2021-23337Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ lodash-4.17.13.tgz (Vulnerable Library) |
High | 7.2 | Proof of concept | 0.9% | lodash-4.17.13.tgz | Upgrade to version: lodash - 4.17.21, lodash-es - 4.17.21 | None |
CVE-2020-28500Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ lodash-4.17.13.tgz (Vulnerable Library) |
Medium | 5.3 | Proof of concept | 0.2% | lodash-4.17.13.tgz | Upgrade to version: lodash - 4.17.21 | None |
Total libraries scanned: 80
Scan token: 317239a8e3d2455dac611004926bd35c
Loading