-
Notifications
You must be signed in to change notification settings - Fork 920
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2022-25858 (High) detected in terser-4.8.0.tgz - autoclosed #1907
Labels
Mend: dependency security vulnerability
Security vulnerability detected by Mend
Comments
mend-for-github.aaakk.us.kg
bot
added
the
Mend: dependency security vulnerability
Security vulnerability detected by Mend
label
Jul 17, 2022
mend-for-github.aaakk.us.kg
bot
changed the title
CVE-2022-25858 (Medium) detected in terser-4.8.0.tgz
CVE-2022-25858 (High) detected in terser-4.8.0.tgz
Jul 25, 2022
✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory. |
mend-for-github.aaakk.us.kg
bot
changed the title
CVE-2022-25858 (High) detected in terser-4.8.0.tgz
CVE-2022-25858 (High) detected in terser-4.8.0.tgz - autoclosed
Jul 27, 2022
ananzh
added a commit
to ananzh/OpenSearch-Dashboards
that referenced
this issue
Mar 29, 2023
Issue Resolved: opensearch-project#1907 Signed-off-by: Anan Zhuang <[email protected]>
ananzh
added a commit
to ananzh/OpenSearch-Dashboards
that referenced
this issue
Mar 29, 2023
Issue Resolved: opensearch-project#1907 Signed-off-by: Anan Zhuang <[email protected]>
8 tasks
ananzh
added a commit
to ananzh/OpenSearch-Dashboards
that referenced
this issue
Mar 29, 2023
Issue Resolved: opensearch-project#1907 Signed-off-by: Anan Zhuang <[email protected]>
ananzh
added a commit
to ananzh/OpenSearch-Dashboards
that referenced
this issue
Mar 30, 2023
Issue Resolved: opensearch-project#1907 Signed-off-by: Anan Zhuang <[email protected]>
ananzh
added a commit
to ananzh/OpenSearch-Dashboards
that referenced
this issue
Mar 30, 2023
Issue Resolved: opensearch-project#1907 Signed-off-by: Anan Zhuang <[email protected]>
joshuarrrr
pushed a commit
that referenced
this issue
Apr 5, 2023
Issue Resolved: #1907 Signed-off-by: Anan Zhuang <[email protected]>
opensearch-trigger-bot bot
pushed a commit
that referenced
this issue
Apr 5, 2023
Issue Resolved: #1907 Signed-off-by: Anan Zhuang <[email protected]> (cherry picked from commit 39818e3) Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> # Conflicts: # CHANGELOG.md
ananzh
pushed a commit
that referenced
this issue
Apr 14, 2023
…3786) * [CVE-2022-25858][1.x] Bump terser from 4.8.0 to 4.8.1 (#3726) Issue Resolved: #1907 Signed-off-by: Anan Zhuang <[email protected]> (cherry picked from commit 39818e3) Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Signed-off-by: Josh Romero <[email protected]> --------- Signed-off-by: Josh Romero <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Josh Romero <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Mend: dependency security vulnerability
Security vulnerability detected by Mend
0 participants
CVE-2022-25858 - High Severity Vulnerability
Vulnerable Library - terser-4.8.0.tgz
JavaScript parser, mangler/compressor and beautifier toolkit for ES6+
Library home page: https://registry.npmjs.org/terser/-/terser-4.8.0.tgz
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
Publish Date: 2022-07-15
URL: CVE-2022-25858
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25858
Release Date: 2022-07-15
Fix Resolution: terser - 4.8.1,5.14.2
The text was updated successfully, but these errors were encountered: