Vulnerability Description
This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gulpjs | Glob-Parent | < 5.1.2 |
| Oracle | Communications Cloud Native Core Policy | 1.14.0 |
Related Weaknesses (CWE)
References
- https://github.com/gulpjs/glob-parent/blob/6ce8d11f2f1ed8e80a9526b1dc8cf3aa71f43Broken Link
- https://github.com/gulpjs/glob-parent/pull/36PatchThird Party Advisory
- https://github.com/gulpjs/glob-parent/releases/tag/v5.1.2Release NotesThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBES128-1059093ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1059092ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905ExploitThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatchThird Party Advisory
- https://github.com/gulpjs/glob-parent/blob/6ce8d11f2f1ed8e80a9526b1dc8cf3aa71f43Broken Link
- https://github.com/gulpjs/glob-parent/pull/36PatchThird Party Advisory
- https://github.com/gulpjs/glob-parent/releases/tag/v5.1.2Release NotesThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBES128-1059093ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1059092ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905ExploitThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatchThird Party Advisory
FAQ
What is CVE-2020-28469?
CVE-2020-28469 is a vulnerability with a CVSS score of 5.3 (MEDIUM). This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.
How severe is CVE-2020-28469?
CVE-2020-28469 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28469?
Check the references section above for vendor advisories and patch information. Affected products include: Gulpjs Glob-Parent, Oracle Communications Cloud Native Core Policy.