Skip to content
This repository was archived by the owner on Feb 3, 2023. It is now read-only.
This repository was archived by the owner on Feb 3, 2023. It is now read-only.

helmet-3.1.0.tgz: 1 vulnerabilities (highest severity is: 6.1) #64

@mend-for-github-com

Description

@mend-for-github-com
Vulnerable Library - helmet-3.1.0.tgz

Vulnerabilities

CVE Severity CVSS Dependency Type Fixed in (helmet version) Remediation Available
WS-2019-0289 Medium 6.1 helmet-csp-2.1.0.tgz Transitive 3.21.0

Details

WS-2019-0289

Vulnerable Library - helmet-csp-2.1.0.tgz

Content Security Policy middleware.

Library home page: https://registry.npmjs.org/helmet-csp/-/helmet-csp-2.1.0.tgz

Dependency Hierarchy:

  • helmet-3.1.0.tgz (Root Library)
    • helmet-csp-2.1.0.tgz (Vulnerable Library)

Found in base branch: main

Vulnerability Details

Helmet-csp before 2.9.1 is vulnerable to a Configuration Override affecting the application's Content Security Policy (CSP). The package's browser sniffing for Firefox deletes the default-src CSP policy, which is the fallback policy. This allows an attacker to remove an application's default CSP, possibly rendering the application vulnerable to Cross-Site Scripting.

Publish Date: 2019-11-18

URL: WS-2019-0289

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.npmjs.com/advisories/1176

Release Date: 2019-11-18

Fix Resolution (helmet-csp): 2.9.1

Direct dependency fix Resolution (helmet): 3.21.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions