This repository has been archived by the owner on Jun 6, 2019. It is now read-only.
WS-2018-0084 (High) detected in sshpk-1.13.0.tgz #30
Labels
security vulnerability
Security vulnerability detected by WhiteSource
WS-2018-0084 - High Severity Vulnerability
Vulnerable Library - sshpk-1.13.0.tgz
A library for finding and using SSH public keys
Library home page: https://registry.npmjs.org/sshpk/-/sshpk-1.13.0.tgz
Dependency Hierarchy:
Found in HEAD commit: 401f73579c289637e10b6a10cb44727b52b03e1b
Vulnerability Details
Versions of sshpk before 1.14.1 are vulnerable to regular expression denial of service when parsing crafted invalid public keys.
Publish Date: 2018-04-25
URL: WS-2018-0084
CVSS 2 Score Details (8.0)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: https://nodesecurity.io/advisories/606
Release Date: 2018-01-27
Fix Resolution: 1.14.1
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: