CVE-2023-2251 (High) detected in yaml-1.10.2.tgz, yaml-2.1.1.tgz - autoclosed #3946
Labels
cve
Security vulnerabilities detected by Dependabot or Mend
Mend: dependency security vulnerability
Security vulnerability detected by Mend
CVE-2023-2251 - High Severity Vulnerability
yaml-1.10.2.tgz
JavaScript parser and stringifier for YAML
Library home page: https://registry.npmjs.org/yaml/-/yaml-1.10.2.tgz
Dependency Hierarchy:
yaml-2.1.1.tgz
JavaScript parser and stringifier for YAML
Library home page: https://registry.npmjs.org/yaml/-/yaml-2.1.1.tgz
Dependency Hierarchy:
Found in base branch: main
Uncaught Exception in GitHub repository eemeli/yaml prior to 2.2.2.
Publish Date: 2023-04-24
URL: CVE-2023-2251
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-f9xv-q969-pqx4
Release Date: 2023-04-24
Fix Resolution (yaml): 2.0.0-0
Direct dependency fix Resolution (stylelint): 15.0.0
Fix Resolution (yaml): 2.2.2
Direct dependency fix Resolution (@percy/cli): 1.11.0
The text was updated successfully, but these errors were encountered: