[Backport 2.x] Add OpenAPI specification for get and create saved object APIs #6801
Mend for GitHub.com / WhiteSource Security Check
failed
May 16, 2024 in 10m 51s
Security Report
You have successfully remediated 5 vulnerabilities, but introduced 5 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
WS-2017-3772Vulnerable Source Files: ❌ /packages/osd-ui-framework/node_modules/underscore.string/unescapeHTML.js |
High | 7.5 | juice-shopjuice-shop-14.0.0_node14_darwin_x64 | Upgrade to version: underscore.string - 3.3.5 | #4734 |
High | 7.5 | lportalliferay-ce-portal-src-7.3.5-ga6-20200930172312275 | #6792 | ||
High | 7.5 | lportalliferay-ce-portal-src-7.3.5-ga6-20200930172312275 | #6791 | ||
CVE-2023-26156Path to dependency file: /package.json Path to vulnerable library: /node_modules/chromedriver/package.json Dependency Hierarchy: -> ❌ chromedriver-107.0.3.tgz (Vulnerable Library) |
High | 7.5 | chromedriver-107.0.3.tgz | Upgrade to version: chromedriver - 119.0.1 | None |
High | 7.5 | lportalliferay-ce-portal-src-7.3.5-ga6-20200930172312275 | Upgrade to version: 6.0.3 | #4726 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-4067 | processmaker-processmaker-3.5.7-community |
CVE-2019-20149 | juice-shop-juice-shop-15.2.0_node16_win32_x64 |
CVE-2023-28155 | request-2.88.12.tgz |
WS-2017-3772 | juice-shop-juice-shop-14.5.1_node16_darwin_x64 |
CVE-2024-4068 | juice-shop-juice-shop-15.2.0_node16_win32_x64 |
Base branch total remaining vulnerabilities: 25
Base branch commit: bd62a5dc00f47f1c47686ceb510e0a73e1870633
Total libraries scanned: 2528
Scan token: 380f54e063e948d5bcd8f31bef01f4fc
Loading