Known vulnerabilities in arborist
Vendor:
npm Inc.
Software:
arborist
Software CPE:
cpe:2.3:a:npm:arborist:*:*:*:*:*:*:*:*
Website:
https://www.npmjs.com/
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
4.1.1
4.1.0
4.0.5
4.0.4
4.0.3
4.0.2
4.0.1
4.0.0
3.0.0
2.10.0
2.9.0
2.8.5
2.8.4
2.8.3
2.8.2
2.8.1
2.8.0
2.7.1
2.7.0
2.6.5
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0
2.5.0
2.4.4
2.4.3
2.4.2
2.4.1
2.4.0
2.3.0
2.2.9
2.2.8
2.2.7
2.2.6
2.2.5
2.2.4
2.2.3
2.2.2
2.2.1
2.2.0
2.1.1
2.1.0
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0
1.0.14
1.0.13
1.0.12
1.0.11
1.0.10
1.0.9
1.0.8
1.0.7
1.0.6
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
0.0.33
0.0.32
0.0.31
0.0.30
0.0.29
0.0.28
0.0.27
0.0.26
0.0.25
0.0.24
0.0.23
0.0.22
0.0.21
0.0.20
0.0.19
0.0.18
0.0.17
0.0.16
0.0.15
0.0.14
0.0.13
0.0.12
0.0.11
0.0.10
0.0.9
0.0.8
0.0.7
0.0.6
0.0.5
0.0.4
0.0.3
0.0.2
0.0.1
0.0.0
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU61257 - UNIX Symbolic Link (Symlink) Following CVE-2021-39135 |
CWE-61 | Low | 2.8.2 | 11.03.2022 |
SB2021083138 SB2022031104 SB2021120224 and 6 more |
||
| #VU61256 - UNIX Symbolic Link (Symlink) Following CVE-2021-39134 |
CWE-61 | Low | 2.8.2 | 11.03.2022 |
SB2021083138 SB2022031104 SB2021120224 and 5 more |