Update dependency ejs to v3 (main) #48
Security Report
You have successfully remediated 3 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Exploit Maturity | EPSS | Vulnerable Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|---|
CVE-2024-43800Path to dependency file: /tutoring/package.json Path to vulnerable library: /tutoring/node_modules/serve-static/package.json,/proctoring/node_modules/serve-static/package.json Dependency Hierarchy: -> express-4.17.1.tgz (Root Library) -> ❌ serve-static-1.14.1.tgz (Vulnerable Library) |
5.0 | Not Defined | 0.1% | serve-static-1.14.1.tgz | Upgrade to version: serve-static - 1.16.0,2.1.0 | #26 | ||
CVE-2024-43799Path to dependency file: /tutoring/package.json Path to vulnerable library: /tutoring/node_modules/send/package.json,/proctoring/node_modules/send/package.json Dependency Hierarchy: -> express-4.17.1.tgz (Root Library) -> ❌ send-0.17.1.tgz (Vulnerable Library) |
5.0 | Not Defined | 0.1% | send-0.17.1.tgz | Upgrade to version: send - 0.19.0 | #26 | ||
CVE-2024-43796Path to dependency file: /tutoring/package.json Path to vulnerable library: /tutoring/node_modules/express/package.json,/proctoring/node_modules/express/package.json Dependency Hierarchy: -> ❌ express-4.17.1.tgz (Vulnerable Library) |
5.0 | Not Defined | 0.1% | express-4.17.1.tgz | Upgrade to version: express - 4.20.0,5.0.0 | #26 |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| WS-2021-0153 | ejs-2.7.4.tgz |
| CVE-2022-29078 | ejs-2.7.4.tgz |
| CVE-2024-33883 | ejs-2.7.4.tgz |
Base branch total remaining vulnerabilities: 25
Base branch commit: null
Total libraries scanned: 125
Scan token: ac2287190ae94fd99670a1bfb18093f5