GHSA-f7xj-rg7h-mc87

    Dashboard / Vulnerabilities / GHSA-f7xj-rg7h-mc87

    GHSA-f7xj-rg7h-mc87

    Published: 7 Jul 2023Last Modified: 13 Jul 2023

    Summary: Stylelint has vulnerability in semver dependency

    Details: ### Summary Our `meow` dependency (which we use for our CLI) depended on `[email protected] `. A vulnerability in this version of `semver` was recently identified and surfaced by `npm audit`: Regular Expression Denial of Service - https://github.com/advisories/GHSA-c2qf-rxjj-qqgw ### Details Original post by the reporter: "my npm audit show the report semver <7.5.2 Severity: moderate semver vulnerable to Regular Expression Denial of Service - https://github.com/advisories/GHSA-c2qf-rxjj-qqgw No fix available And my dependencies tree for semver show your package ├─┬ [email protected] │ └─┬ [email protected] │ └─┬ [email protected] │ └─┬ [email protected] │ └─┬ [email protected] │ └── [email protected] deduped I found that [email protected] contains normalize-package-data@5 and I can fix this vulnerability because it uses semver@7. But I can't update meow to the new major version because your package doesn't allow it." Update your package to use the 'meow' version >=10" ### PoC N/A ### Impact We anticipate the impact to be low as Stylelint is a dev tool and `meow` is only used on the CLI pathway. --- ⬇️ EDITED AFTER PUBLISHED ⬇️ ### Security fix backported to older `semver` versions The same security fix has been backported to older `semver` versions of 5.x and 6.x. See the [CVE-2022-25883](https://github.com/advisories/GHSA-c2qf-rxjj-qqgw) details. So, you can fix this vulnerability by just updating `semver` in your project's dependency tree, instead of updating `stylelint`. For details, see the example: `package.json`: ```json { "dependencies": { "stylelint": "15.10.0" } } ``` Run `npm audit` (here is no alert for `semver`): ```console $ npm ci ... $ npm audit ... stylelint 8.0.0 - 15.10.0 Stylelint has vulnerability in semver dependency - https://github.com/advisories/GHSA-f7xj-rg7h-mc87 fix available via `npm audit fix --force` Will install [email protected], which is outside the stated dependency range node_modules/stylelint 1 low severity vulnerability ... $ npm ls semver ... └─┬ [email protected] └─┬ [email protected] ├─┬ [email protected] │ └── [email protected] └─┬ [email protected] └─┬ [email protected] └─┬ [email protected] └── [email protected] ```

    Affected packages

    Package

    Name: stylelint

    Purl: pkg:npm/stylelint

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 8.0.0
    Fixed -15.10.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-f7xj-rg7h-mc87 | CVE-DB