Vulnerabilities

1 via 1 paths

Dependencies

24

Source

GitHub

Commit

194af453

Find, fix and prevent vulnerabilities in your code.

Severity
  • 1
Status
  • 1
  • 0
  • 0

medium severity

Open Redirect

  • Vulnerable module: got
  • Introduced through: latest-version@3.1.0

Detailed paths

  • Introduced through: npm-package-update-check@rrainn/npm-package-update-check#194af4535ba158cd2a8f22607c123ccc0b1ffa2b latest-version@3.1.0 package-json@4.0.1 got@6.7.1
    Remediation: Upgrade to latest-version@6.0.0.

Overview

Affected versions of this package are vulnerable to Open Redirect due to missing verification of requested URLs. It allowed a victim to be redirected to a UNIX socket.

Remediation

Upgrade got to version 11.8.5, 12.1.0 or higher.

References