Skip to content

CVE-2022-46175 (High) detected in json5-1.0.1 #3305

Closed
@jovancacvetkovic

Description

CVE-2022-46175 - High Severity Vulnerability

Vulnerability Library - JSON5 - 1.0.1

JSON5 - 1.0.1 (current version)
Found in base branch: main

CVSS 3 Score Details - (7.1)

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: High

Suggested Fix

Type: Upgrade version

Release Date: Dec 16, 2022

Fix Resolution: json5 - 1.0.2

More Info

json5 issue resolved with #295

Metadata

Assignees

Labels

cveSecurity vulnerabilities detected by Dependabot or Mend

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions