This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "1.0.2"
}
],
"source": "CPE_RANGE",
"vendor_product": "set_project:set",
"cpes": [
"cpe:2.3:a:set_project:set:*:*:*:*:*:node.js:*:*"
]
},
{
"extracted_events": [
{
"fixed": "1.0.2"
}
],
"source": "DESCRIPTION"
}
]
}