Количество 2
Количество 2
CVE-2023-38695
cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has been patched in version 8.0.2.
GHSA-vxjg-hchx-cc4g
@simonsmith/cypress-image-snapshothas fix for insecure snapshot file names
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-38695 cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has been patched in version 8.0.2. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-vxjg-hchx-cc4g @simonsmith/cypress-image-snapshothas fix for insecure snapshot file names | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу