Update dependency nexmo to v2.2.1 (main) #16
Security Report
❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.
general
https://vonagecc.jfrog.io/artifactory
Step | Level | Description | Details |
---|---|---|---|
Checking registry connectivity | ⚠Warn | Unsupported configuration was provided | Unsupported registry hostType gradle, skipped |
https://vonagecc.jfrog.io/artifactory/maven
Step | Level | Description | Details |
---|---|---|---|
Checking registry connectivity | ⚠Warn | Unsupported configuration was provided | Unsupported registry hostType gradle, skipped |
You have successfully remediated 7 vulnerabilities, but introduced 5 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Exploit Maturity | EPSS | Vulnerable Library | Suggested Fix | Issue | Reachability |
---|---|---|---|---|---|---|---|---|
CVE-2023-26136Path to dependency file: /package.json Path to vulnerable library: /node_modules/tough-cookie/package.json Dependency Hierarchy: -> nexmo-2.2.1.tgz (Root Library) -> request-2.88.2.tgz -> ❌ tough-cookie-2.5.0.tgz (Vulnerable Library) |
Critical | 9.8 | Not Defined | 0.1% | tough-cookie-2.5.0.tgz | Upgrade to version: tough-cookie - 4.1.3 | None | |
CVE-2022-23539Path to dependency file: /package.json Path to vulnerable library: /node_modules/jsonwebtoken/package.json Dependency Hierarchy: -> nexmo-2.2.1.tgz (Root Library) -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library) |
High | 8.1 | Not Defined | 0.1% | jsonwebtoken-8.5.1.tgz | Upgrade to version: jsonwebtoken - 9.0.0 | None | |
CVE-2022-23540Path to dependency file: /package.json Path to vulnerable library: /node_modules/jsonwebtoken/package.json Dependency Hierarchy: -> nexmo-2.2.1.tgz (Root Library) -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library) |
High | 7.6 | Not Defined | 0.1% | jsonwebtoken-8.5.1.tgz | Upgrade to version: jsonwebtoken - 9.0.0 | None | |
CVE-2022-23541Path to dependency file: /package.json Path to vulnerable library: /node_modules/jsonwebtoken/package.json Dependency Hierarchy: -> nexmo-2.2.1.tgz (Root Library) -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library) |
Medium | 6.3 | Not Defined | 0.1% | jsonwebtoken-8.5.1.tgz | Upgrade to version: jsonwebtoken - 9.0.0 | None | |
CVE-2023-28155Path to dependency file: /package.json Path to vulnerable library: /node_modules/request/package.json Dependency Hierarchy: -> nexmo-2.2.1.tgz (Root Library) -> ❌ request-2.88.2.tgz (Vulnerable Library) |
Medium | 6.1 | Not Defined | 0.1% | request-2.88.2.tgz | Upgrade to version: @cypress/request - 3.0.0 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2018-3728 | hoek-2.16.3.tgz |
CVE-2022-24785 | moment-2.19.3.tgz |
CVE-2022-23539 | jsonwebtoken-7.4.3.tgz |
CVE-2022-23541 | jsonwebtoken-7.4.3.tgz |
WS-2018-0096 | base64url-2.0.0.tgz |
CVE-2022-23540 | jsonwebtoken-7.4.3.tgz |
CVE-2022-31129 | moment-2.19.3.tgz |
Base branch total remaining vulnerabilities: 22
Base branch commit: null
Total libraries scanned: 166
Scan token: 890d5d38922e42a1b4afc6ef5e26b565