CVE-2020-7789 (Medium) detected in node-notifier-8.0.0.tgz
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 68/100
Research direction
Start with nozone-example/package.json and inspect the Jest dependency hierarchy to see how node-notifier-8.0.0 is resolved. Upgrade the dependency path so node-notifier resolves to 9.0.0 or later, then verify that the vulnerable 8.0.0 package is no longer present.
Written by the indexing model from the issue text.
Description
CVE-2020-7789 - Medium Severity Vulnerability
Vulnerable Library - node-notifier-8.0.0.tgz
A Node.js module for sending notifications on native Mac, Windows (post and pre 8) and Linux (or Growl as fallback)
Library home page: https://registry.npmjs.org/node-notifier/-/node-notifier-8.0.0.tgz
Path to dependency file: nozone-example/package.json
Path to vulnerable library: nozone-example/node_modules/node-notifier/package.json
Dependency Hierarchy:
- jest-26.2.2.tgz (Root Library)
- core-26.6.3.tgz
- reporters-26.6.2.tgz
- ❌ node-notifier-8.0.0.tgz (Vulnerable Library)
- reporters-26.6.2.tgz
- core-26.6.3.tgz
Found in HEAD commit: d30928f8dd88cc4771a81190f01f6b669c1b9127
Found in base branch: master
Vulnerability Details
This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.
Publish Date: 2020-12-11
URL: CVE-2020-7789
CVSS 3 Score Details (5.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7789
Release Date: 2020-12-11
Fix Resolution: 9.0.0
Step up your Open Source Security Game with WhiteSource here
- Dominant language
- TypeScript
- Stars
- 0
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Jordan-Hall/nozone-example
-
security vulnerability
Difficulty 2/5 1-3 hours Newbie friendliness 45/100
-
security vulnerability
Difficulty 2/5 1-3 hours Newbie friendliness 50/100
-
security vulnerability
Difficulty 2/5 1-3 hours Newbie friendliness 45/100
-
security vulnerability
Difficulty 2/5 1-3 hours Newbie friendliness 45/100
All issues in Jordan-Hall/nozone-example
Similar issues
-
calcite-components needs triage refactor
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Esri/calcite-design-system#15203 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 91/100
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Difficulty 1/5 Under an hour Newbie friendliness 95/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Automattic/studio#4908 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100