8.8
CVSS V3
Status
Impact
This vulnerability is related to the 'mozim' dependency, which is currently at its latest version, though is requiring an older version of dhcproto, which is in turn requiring an older version of trust-dns-proto which is requiring idna 0.2.3 (still vulnerable). Indeed the newest version of trust-dns-proto is requiring idna 0.4.0 (also vulnerable) Waiting on upstream (mozim, dhcproto, and trust-dns-proto) to update requirements to using non-vulnerable idna
Status