-
-
Notifications
You must be signed in to change notification settings - Fork 0
Description
Vulnerable Library - addons-7.6.6.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Found in HEAD commit: 643acc098198f8640772d8a6ea35194839e4b4dc
Vulnerabilities
| Vulnerability | Severity | Dependency | Type | Fixed in (addons version) | Remediation Possible** | |
|---|---|---|---|---|---|---|
| CVE-2024-57556 | 6.1 | store2-2.14.2.tgz | Transitive | 7.6.7 | ❌ |
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2024-57556
Vulnerable Library - store2-2.14.2.tgz
Better localStorage
Library home page: https://registry.npmjs.org/store2/-/store2-2.14.2.tgz
Path to dependency file: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- addons-7.6.6.tgz (Root Library)
- manager-api-7.6.6.tgz
- ❌ store2-2.14.2.tgz (Vulnerable Library)
- manager-api-7.6.6.tgz
Found in HEAD commit: 643acc098198f8640772d8a6ea35194839e4b4dc
Found in base branch: main
Vulnerability Details
Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js component
Publish Date: 2025-01-23
URL: CVE-2024-57556
CVSS 3 Score Details (6.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2025-01-23
Fix Resolution (store2): 2.14.4
Direct dependency fix Resolution (@storybook/addons): 7.6.7
Step up your Open Source Security Game with Mend here