-
-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[FP]: express:4.21.2 | CVE-2024-10491 #7266
Comments
Failed to automatically evaluate the false positive. See: https://github.com/jeremylong/DependencyCheck/actions/runs/12426648292 |
Npm Coordinates npm -i [email protected] Suppression rule: <suppress base="true">
<notes><![CDATA[
FP per issue #7266
]]></notes>
<packageUrl regex="true">^pkg:npm/express@.*$</packageUrl>
<cpe>cpe:/a:N/AC:L/PR</cpe>
</suppress> Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/12446634008 |
Npm Coordinates npm -i [email protected] Suppression rule: <suppress base="true">
<notes><![CDATA[
FP per issue #7266
]]></notes>
<packageUrl regex="true">^pkg:npm/express@.*$</packageUrl>
<cpe>cpe:/a:N/AC:L/PR</cpe>
</suppress> Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/12446653426 |
The (OSSINDEX) behind the CVE indicates that this vuln was sourced from the Sonatype OSSINDEX. You'd have to raise it with them as they list it as affected for this exact version as you can see on https://ossindex.sonatype.org/component/pkg:npm/[email protected] upon sign-in |
Closing as 'won't fix'. This issue must be seen with the ossindex team. |
Package URl
pkg:npm/[email protected]
CPE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE
CVE-2024-10491
ODC Integration
{"label"=>"CLI"}
ODC Version
11.1.1
Description
The vulnerability applies to versions up to and including 3.21.2.
https://ogma.in/cve-2024-10491-mitigating-vulnerability-in-express-response-links
The text was updated successfully, but these errors were encountered: