Update dependency opentok to v2.17.0 #4
Security Report
You have successfully remediated 6 vulnerabilities, but introduced 5 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | |
---|---|---|---|---|---|
CVE-2024-7254Path to dependency file: /VideoExpressAndroid/app/build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.google.protobuf/protobuf-java/3.10.0/410b61dd0088aab4caa05739558d43df248958c9/protobuf-java-3.10.0.jar Dependency Hierarchy: -> lint-gradle-30.0.3.jar (Root Library) -> sdk-common-30.0.3.jar -> ❌ protobuf-java-3.10.0.jar (Vulnerable Library) |
7.5 | protobuf-java-3.10.0.jar | Upgrade to version: com.google.protobuf:protobuf-javalite - 3.25.5,4.28.2,4.27.5;com.google.protobuf:protobuf-java - 4.27.5,3.25.5,4.28.2 | #1 | |
CVE-2024-45590Path to dependency file: /server/package.json Path to vulnerable library: /server/package.json Dependency Hierarchy: -> express-4.18.1.tgz (Root Library) -> ❌ body-parser-1.20.0.tgz (Vulnerable Library) |
7.5 | body-parser-1.20.0.tgz | Upgrade to version: body-parser - 1.20.3 | #6 | |
CVE-2024-30171Path to dependency file: /VideoExpressAndroid/app/build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.bouncycastle/bcprov-jdk15on/1.56/a153c6f9744a3e9dd6feab5e210e1c9861362ec7/bcprov-jdk15on-1.56.jar Dependency Hierarchy: -> lint-gradle-30.0.3.jar (Root Library) -> sdk-common-30.0.3.jar -> ❌ bcprov-jdk15on-1.56.jar (Vulnerable Library) |
5.9 | bcprov-jdk15on-1.56.jar | Upgrade to version: org.bouncycastle:bcprov-jdk15to18:1.78, org.bouncycastle:bcprov-jdk18on:1.78, BouncyCastle.Cryptography - 2.3.1 | #1 | |
CVE-2024-43800Path to dependency file: /server/package.json Path to vulnerable library: /server/package.json Dependency Hierarchy: -> express-4.18.1.tgz (Root Library) -> ❌ serve-static-1.15.0.tgz (Vulnerable Library) |
5.0 | serve-static-1.15.0.tgz | Upgrade to version: serve-static - 1.16.0,2.1.0 | #6 | |
CVE-2024-43799Path to dependency file: /server/package.json Path to vulnerable library: /server/package.json Dependency Hierarchy: -> express-4.18.1.tgz (Root Library) -> ❌ send-0.18.0.tgz (Vulnerable Library) |
5.0 | send-0.18.0.tgz | Upgrade to version: send - 0.19.0 | #6 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2022-23541 | jsonwebtoken-8.5.1.tgz |
CVE-2022-25883 | semver-5.7.1.tgz |
CVE-2022-23540 | jsonwebtoken-8.5.1.tgz |
CVE-2023-26136 | tough-cookie-2.5.0.tgz |
CVE-2022-23539 | jsonwebtoken-8.5.1.tgz |
CVE-2023-28155 | request-2.88.2.tgz |
Base branch total remaining vulnerabilities: 41
Base branch commit: null
Total libraries scanned: 327
Scan token: 89ec8b85b2b44e4aa41fd146721479d6