Skip to content

Incorrect vulnerable range for pkg:npm/%40babel/traverse@7.22.4 #1480

Description

@pombredanne

The public demo DB at https://public.vulnerablecode.io/ has an incorrect vulnerability record for the package pkg:npm/%40babel/traverse@7.22.4

It should report CVE-2023-45133 but https://public.vulnerablecode.io/vulnerabilities/VCID-ay4j-2fpe-aaas?search=CVE-2023-45133 is missing some versions, and still has correctly other versions of the package

This is a bug, but this is a CVE with a weird history and conflicting reports about vulnerable version ranges. These advisories may not all agree for the same CVE:

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions