GHSA-mgv2-57vj-99xc

Suggest an improvement
Source
https://github.com/advisories/GHSA-mgv2-57vj-99xc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-mgv2-57vj-99xc/GHSA-mgv2-57vj-99xc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mgv2-57vj-99xc
Published
2019-10-07T16:54:24Z
Modified
2021-12-03T14:39:45Z
Summary
Low severity vulnerability that affects eye.js
Details

Test breaking

Impact

In v1.2.0, tests are broken: all tests are always succeeding. If tests are looking for security vulnerabilities, these were compromised.

Patches

Users should upgrade to v1.2.1

Workarounds

Users who don't use eye.js for looking for vulnerabilities are safe. Upgrading will just fix some bugs.

For more information

If you have any questions or comments about this advisory:

Database specific
{
    "cwe_ids": [],
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:46:09Z",
    "nvd_published_at": null,
    "severity": "LOW"
}
References

Affected packages

npm / eye.js

Package

Affected ranges

Type
SEMVER
Events
Introduced
1.2.0
Fixed
1.2.1

Affected versions

1.*
1.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-mgv2-57vj-99xc/GHSA-mgv2-57vj-99xc.json"