Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk-local] Fix for 43 vulnerabilities #18

Closed
wants to merge 1 commit into from

Conversation

cfereday
Copy link
Owner

@cfereday cfereday commented Mar 7, 2021

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:

    • package.json
    • package-lock.json
  • Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches.
    Find out more.

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Directory Traversal
SNYK-JS-ADMZIP-1065796
No No Known Exploit
high severity Internal Property Tampering
SNYK-JS-BSON-561052
Yes No Known Exploit
medium severity Arbitrary Code Injection
SNYK-JS-EJS-1049328
Yes Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-EXPRESSFILEUPLOAD-473997
Yes No Known Exploit
high severity Prototype Pollution
SNYK-JS-EXPRESSFILEUPLOAD-595969
Yes Proof of Concept
high severity Prototype Pollution
SNYK-JS-INI-1048974
Yes Proof of Concept
medium severity Prototype Pollution
SNYK-JS-JQUERY-174006
Yes Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-JQUERY-565129
Yes Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-JQUERY-567880
Yes Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
No Proof of Concept
high severity Command Injection
SNYK-JS-LODASH-1040724
No Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-174116
No No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-451540
No No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS )
SNYK-JS-MARKED-584281
Yes No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-1019388
No No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-MONGODB-473855
Yes No Known Exploit
high severity Prototype Pollution
SNYK-JS-MQUERY-1050858
Yes No Known Exploit
critical severity Improper Access Control
SNYK-JS-NEXTAUTH-1072465
No No Known Exploit
high severity Prototype Pollution
SNYK-JS-NODEFORGE-598677
No Proof of Concept
medium severity Prototype Pollution
SNYK-JS-YARGSPARSER-560381
Yes Proof of Concept
low severity Insecure use of /tmp folder
npm:cli:20160615
No No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
No No Known Exploit
high severity Arbitrary Code Execution
npm:ejs:20161128
Yes No Known Exploit
medium severity Cross-site Scripting (XSS)
npm:ejs:20161130
Yes No Known Exploit
medium severity Denial of Service (DoS)
npm:ejs:20161130-1
Yes No Known Exploit
medium severity Cross-site Scripting (XSS)
npm:jquery:20150627
Yes No Known Exploit
high severity Cross-site Scripting (XSS)
npm:marked:20150520
No No Known Exploit
high severity Cross-site Scripting (XSS)
npm:marked:20170112
No No Known Exploit
high severity Cross-site Scripting (XSS)
npm:marked:20170815
No No Known Exploit
medium severity Cross-site Scripting (XSS)
npm:marked:20170815-1
No No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
npm:marked:20170907
No No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
npm:marked:20180225
No Proof of Concept
medium severity Denial of Service (DoS)
npm:mem:20180117
Yes No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:mime:20170907
Yes No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
npm:minimatch:20160620
No No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:ms:20170412
Yes No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
npm:negotiator:20160616
Yes No Known Exploit
high severity Uninitialized Memory Exposure
npm:npmconf:20180512
Yes Mature
medium severity Regular Expression Denial of Service (ReDoS)
npm:semver:20150403
Yes No Known Exploit
medium severity Directory Traversal
npm:st:20140206
No Proof of Concept
medium severity Open Redirect
npm:st:20171013
Yes Mature
Commit messages
Package name: adm-zip The new version differs by 84 commits.

See the full diff

Package name: body-parser The new version differs by 53 commits.
  • b2659a7 1.18.2
  • 6339bf7 perf: remove argument reassignment
  • d5f9a4a deps: debug@2.6.9
  • d041563 1.18.1
  • 9efa9ab deps: content-type@~1.0.4
  • f1ef6cc deps: qs@6.5.1
  • e438db5 deps: raw-body@2.3.2
  • 15c3585 deps: iconv-lite@0.4.19
  • adfa01c 1.18.0
  • 0632e2f Include the "type" property on all generated errors
  • b8f97cd Include the "body" property on verify errors
  • c659e8a tests: add test for err.body on json parse error
  • 4e15325 tests: reorganize json error tests
  • 5bd7ed5 tests: reorganize json strict option tests
  • 3cb380b tests: store server on mocha context instead of variable shadowing
  • 29c8cd0 docs: document too many parameters error
  • 7b9cb14 Use http-errors to set status code on errors
  • 29a27f1 docs: fix typo in jsdoc comment
  • 448dc57 Fix JSON strict violation error to match native parse error
  • 87df7e6 tests: add leading whitespace strict json test
  • 1841248 deps: raw-body@2.3.1
  • e666dbe deps: http-errors@~1.6.2
  • c2a110a deps: bytes@3.0.0
  • a1a2e31 build: Node.js@8.4

See the full diff

Package name: express-fileupload The new version differs by 250 commits.

See the full diff

Package name: lodash The new version differs by 1 commits.

See the full diff

Package name: marked The new version differs by 250 commits.
  • 1ad8e69 Merge pull request #1731 from UziTech/release-1.1.1
  • 7e17526 1.1.1
  • 7fbee6e Merge pull request #1730 from UziTech/update-deps
  • 6f7522f Merge pull request #1729 from UziTech/quick-ref
  • f8024eb remove ending slash
  • 524ae66 remove ending slash
  • 0d6e056 build
  • 04ac593 update dev deps
  • f36f676 🗜️ build [skip ci]
  • dddf9ae Merge pull request #1686 from calculuschild/EmphasisFixes
  • 6b729ed Merge branch 'EmphasisFixes' of https://github.com/calculuschild/marked into EmphasisFixes
  • e27e6f9 Sorted strong and em into sub-objects
  • a761316 Merge pull request #1726 from UziTech/show-rules
  • f8193ed add npm run rules
  • ad720c1 Make emEnd const
  • 1fb141d Make strEnd const
  • 226bbe7 Lint
  • cc778ad Removed redundancy in "startEM" check
  • 211b9f9 Removed Lookbehinds
  • 982b57e Merge pull request #1720 from vassudanagunta/docs-patch-1
  • 2a847e6 clarify level of support for Markdown flavors
  • bd4f8c4 Fix unrestricted "any character" for REDOS
  • 4e7902e Gaaaah lint
  • 4db32dc Links are masked only once per inline string

See the full diff

Package name: mongoose The new version differs by 250 commits.
  • d7fc59c chore: release 5.11.7
  • d318339 fix(index.d.ts): make `Document#id` optional so types that use `id` can use `Model<IMyType & Document>`
  • a9b317a chore: upgrade mquery -> 3.2.3
  • 43f88db fix(document): ensure calling `get()` with empty string returns undefined for mongoose-plugin-autoinc
  • 369efe1 Merge pull request #9692 from sahasayan/patch-4
  • f879c4d chore: update opencollective sponsors
  • 1be4d87 fix(model): set `isNew` to false for documents that were successfully inserted by `insertMany` with `ordered = false` when an error occurred
  • b2da840 test(model): repro #9677
  • 15d6660 fix(index.d.ts): add missing Aggregate#skip() & Aggregate#limit()
  • dd348b1 chore: release 5.11.6
  • 3ec01fa fix(index.d.ts): allow calling `mongoose.model()` and `Connection#model()` with model as generic param
  • ccfa041 Merge pull request #9686 from cjroebuck/patch-1
  • 7a52e45 Merge pull request #9685 from sahasayan/patch-3
  • a5c98c2 Allow array of validators in SchemaTypeOptions
  • 48907ea fix(index.d.ts): allow 2 generic types in mongoose.model function
  • a17a2c3 Merge pull request #9683 from isengartz/master
  • 61595f0 fix(index.d.ts): allow passing ObjectId properties as strings to `create()` and `findOneAndReplace()`
  • 8e20ee6 optional next() parameter for post middleware
  • 8a52485 Merge pull request #9680 from orgads/aggregate
  • 1ef8274 fix(middleware): ensure sync errors in pre hooks always bubble up to the calling code
  • 067e3a2 fix(index.d.ts): Fix return type of Model#aggregate()
  • 0e2058d chore: release 5.11.5
  • 6d9fb4d fix(index.d.ts): add missing `SchemaTypeOpts` and `ConnectionOptions` aliases for backwards compat
  • a85adb9 test: fix tests re: #9669

See the full diff

Package name: ms The new version differs by 19 commits.

See the full diff

Package name: next-auth The new version differs by 250 commits.

See the full diff

Package name: tap The new version differs by 110 commits.

See the full diff

With a Snyk patch:
Severity Issue Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-LODASH-567746
Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
npm:ms:20151024
No Known Exploit

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- http://localhost:8000/vuln/SNYK-JS-ADMZIP-1065796
- http://localhost:8000/vuln/SNYK-JS-BSON-561052
- http://localhost:8000/vuln/SNYK-JS-EJS-1049328
- http://localhost:8000/vuln/SNYK-JS-EXPRESSFILEUPLOAD-473997
- http://localhost:8000/vuln/SNYK-JS-EXPRESSFILEUPLOAD-595969
- http://localhost:8000/vuln/SNYK-JS-INI-1048974
- http://localhost:8000/vuln/SNYK-JS-JQUERY-174006
- http://localhost:8000/vuln/SNYK-JS-JQUERY-565129
- http://localhost:8000/vuln/SNYK-JS-JQUERY-567880
- http://localhost:8000/vuln/SNYK-JS-LODASH-1018905
- http://localhost:8000/vuln/SNYK-JS-LODASH-1040724
- http://localhost:8000/vuln/SNYK-JS-MARKED-174116
- http://localhost:8000/vuln/SNYK-JS-MARKED-451540
- http://localhost:8000/vuln/SNYK-JS-MARKED-584281
- http://localhost:8000/vuln/SNYK-JS-MINIMATCH-1019388
- http://localhost:8000/vuln/SNYK-JS-MONGODB-473855
- http://localhost:8000/vuln/SNYK-JS-MQUERY-1050858
- http://localhost:8000/vuln/SNYK-JS-NEXTAUTH-1072465
- http://localhost:8000/vuln/SNYK-JS-NODEFORGE-598677
- http://localhost:8000/vuln/SNYK-JS-YARGSPARSER-560381
- http://localhost:8000/vuln/npm:cli:20160615
- http://localhost:8000/vuln/npm:debug:20170905
- http://localhost:8000/vuln/npm:ejs:20161128
- http://localhost:8000/vuln/npm:ejs:20161130
- http://localhost:8000/vuln/npm:ejs:20161130-1
- http://localhost:8000/vuln/npm:jquery:20150627
- http://localhost:8000/vuln/npm:marked:20150520
- http://localhost:8000/vuln/npm:marked:20170112
- http://localhost:8000/vuln/npm:marked:20170815
- http://localhost:8000/vuln/npm:marked:20170815-1
- http://localhost:8000/vuln/npm:marked:20170907
- http://localhost:8000/vuln/npm:marked:20180225
- http://localhost:8000/vuln/npm:mem:20180117
- http://localhost:8000/vuln/npm:mime:20170907
- http://localhost:8000/vuln/npm:minimatch:20160620
- http://localhost:8000/vuln/npm:ms:20170412
- http://localhost:8000/vuln/npm:negotiator:20160616
- http://localhost:8000/vuln/npm:npmconf:20180512
- http://localhost:8000/vuln/npm:semver:20150403
- http://localhost:8000/vuln/npm:st:20140206
- http://localhost:8000/vuln/npm:st:20171013


The following vulnerabilities are fixed with a Snyk patch:
- http://localhost:8000/vuln/SNYK-JS-LODASH-567746
- http://localhost:8000/vuln/npm:ms:20151024
@cfereday cfereday closed this Mar 11, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants