Skip to content

video.js-8.12.0.tgz: 2 vulnerabilities (highest severity is: 6.9) [master]Β #16

@mend-developer-platform-dev

Description

@mend-developer-platform-dev
πŸ“‚ Vulnerable Library - video.js-8.12.0.tgz

Path to dependency file: /frontend/package.json

Path to vulnerable library: /frontend/node_modules/video.js/package.json

Findings

Finding Severity 🎯 CVSS Exploit Maturity EPSS Library Type Fixed in Remediation Available Reachability
CVE-2021-32796 🟠 Medium 6.9 Not Defined < 1% xmldom-0.8.10.tgz Transitive N/A ❌
CVE-2024-4011 🟑 Low 2.3 Not Defined < 1% xmldom-0.8.10.tgz Transitive N/A ❌

Details

🟠CVE-2021-32796

Vulnerable Library - xmldom-0.8.10.tgz

Library home page: https://registry.npmjs.org/@xmldom/xmldom/-/xmldom-0.8.10.tgz

Path to dependency file: /frontend/package.json

Path to vulnerable library: /frontend/node_modules/@xmldom/xmldom/package.json

Dependency Hierarchy:

  • video.js-8.12.0.tgz (Root Library)
    • mpd-parser-1.3.0.tgz
      • ❌ xmldom-0.8.10.tgz (Vulnerable Library)

Vulnerability Details

xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This issue has been resolved in version 0.7.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.

Publish Date: Jul 27, 2021 09:45 PM

URL: CVE-2021-32796

Threat Assessment

Exploit Maturity:Not Defined

EPSS:< 1%

Score: 6.9


Suggested Fix

Type: Upgrade version

Origin: GHSA-5fg8-2547-mr8q

Release Date: Jul 27, 2021 09:45 PM

Fix Resolution : @xmldom/xmldom - 0.7.0

🟑CVE-2024-4011

Vulnerable Library - xmldom-0.8.10.tgz

Library home page: https://registry.npmjs.org/@xmldom/xmldom/-/xmldom-0.8.10.tgz

Path to dependency file: /frontend/package.json

Path to vulnerable library: /frontend/node_modules/@xmldom/xmldom/package.json

Dependency Hierarchy:

  • video.js-8.12.0.tgz (Root Library)
    • mpd-parser-1.3.0.tgz
      • ❌ xmldom-0.8.10.tgz (Vulnerable Library)

Vulnerability Details

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.

Publish Date: Jun 26, 2024 11:31 PM

URL: CVE-2024-4011

Threat Assessment

Exploit Maturity:Not Defined

EPSS:< 1%

Score: 2.3


Suggested Fix

Type: Upgrade version

Origin: https://www.cve.org/CVERecord?id=CVE-2024-4011

Release Date: Jun 26, 2024 11:31 PM

Fix Resolution : v16.11.5,v17.0.3,v17.1.1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions