Severity
Medium
Short Description
Contains a medium severity Common Vulnerability and Exposure (CVE).
Suggestion
Remove or replace dependencies that include known medium severity CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.
A Medium CVE (Common Vulnerabilities and Exposures) alert indicates a moderate security vulnerability within a package that poses a reasonable risk to your system. CVEs are standardized identifiers for known security vulnerabilities in software.
Socket’s AI-powered threat detection flags packages with medium CVEs to ensure they are documented and addressed appropriately. These vulnerabilities, while not critical, can still pose significant risks if left unpatched.
Why Medium CVEs are Important
Medium CVEs indicate moderate security vulnerabilities that pose a reasonable risk to your system.
Suggested Action Configuration
Alert Action: Monitor
Investigate the Dependency
Apply Patches or Updates
Monitor for Updates
Example Response
For example, if you receive a medium CVE alert for a popular npm package, you should:
Examples of Medium CVEs
Socket integrates with the GitHub Security Advisory Database to ingest Common Vulnerabilities and Exposures (CVEs) and other security advisories.
Medium CVEs:
By integrating with the GitHub Security Advisory Database, Socket provides robust protection against vulnerabilities in open-source dependencies.
GitHub Security Advisory Database:
The GitHub Security Advisory Database is a comprehensive resource that contains security advisories from various sources, including the National Vulnerability Database (NVD), community submissions, and advisories curated by GitHub. It helps developers stay informed about vulnerabilities that could affect their projects.
For more information about the GitHub Security Advisory Database, visit GitHub Advisory Database.
National Vulnerability Database (NVD):
MITRE CVE Database:
GitHub Security Advisories:
CVE Details:
Socket Blog: