mechanize@0.3.7 vulnerabilities

Stateful, programmatic web browsing

  • latest version

    0.4.10

  • latest non vulnerable version

  • first published

    16 years ago

  • latest version published

    8 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the mechanize package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Regular Expression Denial of Service (ReDoS)

    mechanize is a Stateful, programmatic web browsing

    Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expression in the compile method used in the AbstractBasicAuthHandler class. Exploiting this vulnerability is possible when parsing a malformed auth header.

    How to fix Regular Expression Denial of Service (ReDoS)?

    Upgrade mechanize to version 0.4.6 or higher.

    [,0.4.6)