Update dependency nexmo to v2.4.1 (main) #7
Security Report
You have successfully remediated 7 vulnerabilities, but introduced 6 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Exploit Maturity | EPSS | Vulnerable Library | Suggested Fix | Issue | Reachability | |
---|---|---|---|---|---|---|---|---|
CVE-2023-26136Path to dependency file: /package.json Path to vulnerable library: /node_modules/tough-cookie/package.json Dependency Hierarchy: -> nexmo-2.4.1.tgz (Root Library) -> request-2.88.2.tgz -> ❌ tough-cookie-2.5.0.tgz (Vulnerable Library) |
6.5 | Proof of concept | 0.5% | tough-cookie-2.5.0.tgz | Upgrade to version: tough-cookie - 4.1.3 | None | ||
CVE-2022-23540Path to dependency file: /package.json Path to vulnerable library: /node_modules/jsonwebtoken/package.json Dependency Hierarchy: -> nexmo-2.4.1.tgz (Root Library) -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library) |
6.4 | Not Defined | 0.1% | jsonwebtoken-8.5.1.tgz | Upgrade to version: jsonwebtoken - 9.0.0 | None | ||
CVE-2023-28155Path to dependency file: /package.json Path to vulnerable library: /node_modules/request/package.json Dependency Hierarchy: -> nexmo-2.4.1.tgz (Root Library) -> ❌ request-2.88.2.tgz (Vulnerable Library) |
6.1 | Not Defined | 0.1% | request-2.88.2.tgz | Upgrade to version: @cypress/request - 3.0.0 | None | ||
CVE-2022-23539Path to dependency file: /package.json Path to vulnerable library: /node_modules/jsonwebtoken/package.json Dependency Hierarchy: -> nexmo-2.4.1.tgz (Root Library) -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library) |
5.9 | Not Defined | 0.1% | jsonwebtoken-8.5.1.tgz | Upgrade to version: jsonwebtoken - 9.0.0 | None | ||
CVE-2024-43800Path to dependency file: /package.json Path to vulnerable library: /node_modules/serve-static/package.json Dependency Hierarchy: -> express-4.16.4.tgz (Root Library) -> ❌ serve-static-1.13.2.tgz (Vulnerable Library) |
5.0 | Not Defined | 0.1% | serve-static-1.13.2.tgz | Upgrade to version: serve-static - 1.16.0,2.1.0 | #10 | ||
CVE-2022-23541Path to dependency file: /package.json Path to vulnerable library: /node_modules/jsonwebtoken/package.json Dependency Hierarchy: -> nexmo-2.4.1.tgz (Root Library) -> ❌ jsonwebtoken-8.5.1.tgz (Vulnerable Library) |
5.0 | Not Defined | 0.1% | jsonwebtoken-8.5.1.tgz | Upgrade to version: jsonwebtoken - 9.0.0 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2022-23540 | jsonwebtoken-8.4.0.tgz |
CVE-2020-15366 | ajv-6.6.2.tgz |
CVE-2022-23541 | jsonwebtoken-8.4.0.tgz |
CVE-2021-3918 | json-schema-0.2.3.tgz |
CVE-2022-23539 | jsonwebtoken-8.4.0.tgz |
CVE-2023-26136 | tough-cookie-2.4.3.tgz |
CVE-2023-28155 | request-2.88.0.tgz |
Base branch total remaining vulnerabilities: 15
Base branch commit: null
Total libraries scanned: 107
Scan token: e224b059157b494dabd7d37ba358ae09