GoogleCloudPlatform / GoogleCloudPlatform/synthetics-sdk-nodejs
Critical vulnerabilities in synthetics-sdk-mocha
- Dominant language
- TypeScript
- Stars
- 19
- Forks
- 13
- PR merge metrics
- No merged PRs in 30d
Description
serialize-javascript <=7.0.4
Severity: high
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() - https://github.com/advisories/GHSA-5c6j-r48x-rmvq
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects - https://github.com/advisories/GHSA-qj8w-gfj5-8c6v
No fix available
node_modules/serialize-javascript
mocha 8.0.0 - 12.0.0-beta-2
Depends on vulnerable versions of serialize-javascript
node_modules/mocha
@google-cloud/synthetics-sdk-mocha *
Depends on vulnerable versions of mocha
node_modules/@google-cloud/synthetics-sdk-mocha
Contributor guide
Assessment
This issue has not been assessed yet.