aquasecurity / aquasecurity/cloudsploit
CVE-2024-21538: HIGH vulnerability in cross-spawn dependency
- Dominant language
- JavaScript
- Stars
- 3.8k
- Forks
- 751
- Avg merge
- 11d 9h
- Merged PRs (30d)
- 3
Description
Hello,
There's a HIGH finding in the package cross-spawn, that is a dependency of quite a few packages (eslint among those).
Would it be possible to bump those packages? And eventually setup trivy or other tools to avoid these in the future?
Finding: https://avd.aquasec.com/nvd/2024/cve-2024-21538/
Thanks!
Jules
Contributor guide
Research direction
No source file, test, or entry point is named. Start by reviewing the dependency references to cross-spawn and the linked CVE, then determine which packages can be updated; done would require addressing the vulnerable dependency and clarifying whether a future scanner such as Trivy is in scope.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100