Junglewise Threat Intelligence

validator moderate severity vulnerability

Severity: info · Published 2017-10-24

Vendors: npm.

Executive brief

The validator npm package contains a moderate severity vulnerability affecting versions prior to 2.0.0. This advisory has been withdrawn as a duplicate of another advisory, indicating the issue was already tracked under a separate report. Organizations using older versions of this library should upgrade to version 2.0.0 or later.

Technical details

This vulnerability was reported against the validator npm package, a data validation library. The advisory was withdrawn on 2020-06-17 as a duplicate of GHSA-79mx-88w7-8f7q, indicating the issue was already tracked under that separate advisory identifier. The affected versions are all releases prior to version 2.0.0. No CVE assignment was made for this duplicate advisory. Detailed technical information is not available in this withdrawn advisory; refer to the original advisory GHSA-79mx-88w7-8f7q for full vulnerability details and remediation guidance.

Affected products

  • npm validator < 2.0.0

Timeline

  • 2017-10-24: disclosed
  • 2020-06-17: withdrawn: Duplicate of GHSA-79mx-88w7-8f7q