aquasecurity / aquasecurity/cloudsploit

CVE-2024-21538: HIGH vulnerability in cross-spawn dependency

Open
#2,128 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
3.8k
Forks
751
Avg merge
11d 9h
Merged PRs (30d)
3

Description

Hello,

There's a HIGH finding in the package cross-spawn, that is a dependency of quite a few packages (eslint among those).
Would it be possible to bump those packages? And eventually setup trivy or other tools to avoid these in the future?
Finding: https://avd.aquasec.com/nvd/2024/cve-2024-21538/

Thanks!
Jules

Contributor guide

Open the contributing guide

Research direction

No source file, test, or entry point is named. Start by reviewing the dependency references to cross-spawn and the linked CVE, then determine which packages can be updated; done would require addressing the vulnerable dependency and clarifying whether a future scanner such as Trivy is in scope.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.