Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Found high level security vulnerability for websocket-extensions in BlackDuck scans #10

Closed
aakritidhawan opened this issue Aug 18, 2020 · 1 comment

Comments

@aakritidhawan
Copy link

aakritidhawan commented Aug 18, 2020

While running BlackDuck scans for a project, found 1 High level security vulnerability for websocket-extensions version 0.1.4.
BlackDuck scan message-
image

There is no newer version available for websocket-extensions to fix this issue.

@jcoglan
Copy link
Collaborator

jcoglan commented Aug 18, 2020

As you will see if you check the security advisories on this repository, this issue has already been fixed in this package: GHSA-g78m-2chm-r7qv.

The message you're seeing here is for the Ruby version of the package, which has also fixed the issue: GHSA-g6wq-qcwm-j5g2.

I've had another report of Black Duck reporting this issue against the wrong package, you should probably advise the vendor that their software is raising a warning incorrectly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants