-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Fix for 29 vulnerabilities #6
base: main
Are you sure you want to change the base?
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-ISTANBULREPORTS-2328088 - https://snyk.io/vuln/SNYK-JS-JQUERY-174006 - https://snyk.io/vuln/SNYK-JS-JQUERY-565129 - https://snyk.io/vuln/SNYK-JS-JQUERY-567880 - https://snyk.io/vuln/SNYK-JS-MARKED-174116 - https://snyk.io/vuln/SNYK-JS-MARKED-2342073 - https://snyk.io/vuln/SNYK-JS-MARKED-2342082 - https://snyk.io/vuln/SNYK-JS-MARKED-451540 - https://snyk.io/vuln/SNYK-JS-MARKED-584281 - https://snyk.io/vuln/SNYK-JS-QS-3153490 - https://snyk.io/vuln/SNYK-JS-TYPEORM-590152 - https://snyk.io/vuln/SNYK-JS-UGLIFYJS-1727251 - https://snyk.io/vuln/SNYK-JS-UNDERSCORE-1080984 - https://snyk.io/vuln/SNYK-JS-VALIDATOR-1090599 - https://snyk.io/vuln/SNYK-JS-VALIDATOR-1090600 - https://snyk.io/vuln/SNYK-JS-VALIDATOR-1090601 - https://snyk.io/vuln/SNYK-JS-VALIDATOR-1090602 - https://snyk.io/vuln/SNYK-JS-XML2JS-5414874 - https://snyk.io/vuln/SNYK-JS-Y18N-1021887 - https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381 - https://snyk.io/vuln/npm:jquery:20150627 - https://snyk.io/vuln/npm:mem:20180117 - https://snyk.io/vuln/npm:mime:20170907 - https://snyk.io/vuln/npm:ms:20170412 - https://snyk.io/vuln/npm:negotiator:20160616 - https://snyk.io/vuln/npm:npmconf:20180512 - https://snyk.io/vuln/npm:qs:20170213 - https://snyk.io/vuln/npm:semver:20150403 - https://snyk.io/vuln/npm:st:20171013
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Bridgecrew has found errors in this PR ⬇️
@@ -16,37 +16,37 @@ | |||
}, | |||
"dependencies": { | |||
"adm-zip": "0.4.7", | |||
"body-parser": "1.9.0", | |||
"cfenv": "^1.0.4", | |||
"body-parser": "1.19.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
mongoose 4.2.4 / package.json
Total vulnerabilities: 5
Critical: 3 | High: 1 | Medium: 1 | Low: 0 |
---|
Vulnerability ID | Severity | CVSS | Fixed in | Status |
---|---|---|---|---|
CVE-2022-2564 | CRITICAL | 9.8 | 6.4.6 |
Open |
CVE-2019-17426 | CRITICAL | 9.1 | - |
Open |
CVE-2023-3696 | CRITICAL | 9.8 | 5.13.20 |
Open |
PRISMA-2021-0067 | HIGH | - | 5.12.2 |
Open |
GHSA-r5xw-q988-826m | MEDIUM | 5.1 | 4.3.6 |
Open |
@@ -16,37 +16,37 @@ | |||
}, | |||
"dependencies": { | |||
"adm-zip": "0.4.7", | |||
"body-parser": "1.9.0", | |||
"cfenv": "^1.0.4", | |||
"body-parser": "1.19.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lodash 4.17.4 / package.json
Total vulnerabilities: 7
Critical: 1 | High: 2 | Medium: 4 | Low: 0 |
---|
Vulnerability ID | Severity | CVSS | Fixed in | Status |
---|---|---|---|---|
CVE-2019-10744 | CRITICAL | 9.1 | 4.17.12 |
Open |
CVE-2021-23337 | HIGH | 7.2 | 4.17.21 |
Open |
CVE-2020-8203 | HIGH | 7.4 | 4.17.20 |
Open |
CVE-2020-28500 | MEDIUM | 5.3 | 4.17.21 |
Open |
CVE-2019-1010266 | MEDIUM | 6.5 | 4.17.11 |
Open |
CVE-2018-3721 | MEDIUM | 6.5 | 4.17.5 |
Open |
CVE-2018-16487 | MEDIUM | 5.6 | 4.17.11 |
Open |
@@ -16,37 +16,37 @@ | |||
}, | |||
"dependencies": { | |||
"adm-zip": "0.4.7", | |||
"body-parser": "1.9.0", | |||
"cfenv": "^1.0.4", | |||
"body-parser": "1.19.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
file-type 8.1.0 / package.json
Total vulnerabilities: 1
Critical: 0 | High: 0 | Medium: 1 | Low: 0 |
---|
Vulnerability ID | Severity | CVSS | Fixed in | Status |
---|---|---|---|---|
CVE-2022-36313 | MEDIUM | 5.5 | 16.5.4 |
Open |
@@ -16,37 +16,37 @@ | |||
}, | |||
"dependencies": { | |||
"adm-zip": "0.4.7", | |||
"body-parser": "1.9.0", | |||
"cfenv": "^1.0.4", | |||
"body-parser": "1.19.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
adm-zip 0.4.7 / package.json
Total vulnerabilities: 2
Critical: 0 | High: 1 | Medium: 1 | Low: 0 |
---|
Vulnerability ID | Severity | CVSS | Fixed in | Status |
---|---|---|---|---|
PRISMA-2021-0034 | HIGH | - | 0.5.3 |
Open |
CVE-2018-1002204 | MEDIUM | 5.5 | 0.4.9 |
Open |
@@ -16,37 +16,37 @@ | |||
}, | |||
"dependencies": { | |||
"adm-zip": "0.4.7", | |||
"body-parser": "1.9.0", | |||
"cfenv": "^1.0.4", | |||
"body-parser": "1.19.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
dustjs-linkedin 2.5.0 / package.json
Total vulnerabilities: 1
Critical: 0 | High: 1 | Medium: 0 | Low: 0 |
---|
Vulnerability ID | Severity | CVSS | Fixed in | Status |
---|---|---|---|---|
CVE-2021-4264 | HIGH | 8.8 | 3.0.0 |
Open |
@@ -16,37 +16,37 @@ | |||
}, | |||
"dependencies": { | |||
"adm-zip": "0.4.7", | |||
"body-parser": "1.9.0", | |||
"cfenv": "^1.0.4", | |||
"body-parser": "1.19.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
hbs 4.1.2 / package.json
Total vulnerabilities: 1
Critical: 0 | High: 0 | Medium: 1 | Low: 0 |
---|
Vulnerability ID | Severity | CVSS | Fixed in | Status |
---|---|---|---|---|
CVE-2021-32822 | MEDIUM | 4 | - |
Open |
@@ -16,37 +16,37 @@ | |||
}, | |||
"dependencies": { | |||
"adm-zip": "0.4.7", | |||
"body-parser": "1.9.0", | |||
"cfenv": "^1.0.4", | |||
"body-parser": "1.19.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
moment 2.15.1 / package.json
Total vulnerabilities: 2
Critical: 0 | High: 2 | Medium: 0 | Low: 0 |
---|
Vulnerability ID | Severity | CVSS | Fixed in | Status |
---|---|---|---|---|
CVE-2022-24785 | HIGH | 7.5 | 2.29.2 |
Open |
CVE-2017-18214 | HIGH | 7.5 | 2.19.3 |
Open |
@@ -16,37 +16,37 @@ | |||
}, | |||
"dependencies": { | |||
"adm-zip": "0.4.7", | |||
"body-parser": "1.9.0", | |||
"cfenv": "^1.0.4", | |||
"body-parser": "1.19.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
ejs 1.0.0 / package.json
Total vulnerabilities: 3
Critical: 1 | High: 1 | Medium: 1 | Low: 0 |
---|
Vulnerability ID | Severity | CVSS | Fixed in | Status |
---|---|---|---|---|
CVE-2017-1000228 | CRITICAL | 9.8 | 2.5.5 |
Open |
CVE-2017-1000189 | HIGH | 7.5 | 2.5.5 |
Open |
CVE-2017-1000188 | MEDIUM | 6.1 | 2.5.5 |
Open |
@@ -16,37 +16,37 @@ | |||
}, | |||
"dependencies": { | |||
"adm-zip": "0.4.7", | |||
"body-parser": "1.9.0", | |||
"cfenv": "^1.0.4", | |||
"body-parser": "1.19.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@@ -16,37 +16,37 @@ | |||
}, | |||
"dependencies": { | |||
"adm-zip": "0.4.7", | |||
"body-parser": "1.9.0", | |||
"cfenv": "^1.0.4", | |||
"body-parser": "1.19.2", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Comment
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Has a fix available, CVSS 4.3
SNYK-JS-ISTANBULREPORTS-2328088
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
SNYK-JS-JQUERY-174006
Why? Mature exploit, Has a fix available, CVSS 6.3
SNYK-JS-JQUERY-565129
Why? Mature exploit, Has a fix available, CVSS 6.5
SNYK-JS-JQUERY-567880
Why? Has a fix available, CVSS 5.3
SNYK-JS-MARKED-174116
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-MARKED-2342073
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-MARKED-2342082
Why? Has a fix available, CVSS 5.3
SNYK-JS-MARKED-451540
Why? Has a fix available, CVSS 5.9
SNYK-JS-MARKED-584281
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-QS-3153490
Why? Mature exploit, Has a fix available, CVSS 8.3
SNYK-JS-TYPEORM-590152
Why? Has a fix available, CVSS 5.3
SNYK-JS-UGLIFYJS-1727251
Why? Proof of Concept exploit, Has a fix available, CVSS 5.5
SNYK-JS-UNDERSCORE-1080984
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-VALIDATOR-1090599
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-VALIDATOR-1090600
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-VALIDATOR-1090601
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-VALIDATOR-1090602
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
SNYK-JS-XML2JS-5414874
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
SNYK-JS-Y18N-1021887
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
SNYK-JS-YARGSPARSER-560381
Why? Has a fix available, CVSS 5.4
npm:jquery:20150627
Why? Has a fix available, CVSS 5.1
npm:mem:20180117
Why? Has a fix available, CVSS 3.7
npm:mime:20170907
Why? Has a fix available, CVSS 3.7
npm:ms:20170412
Why? Has a fix available, CVSS 7.5
npm:negotiator:20160616
Why? Mature exploit, Has a fix available, CVSS 7.4
npm:npmconf:20180512
Why? Has a fix available, CVSS 7.5
npm:qs:20170213
Why? Has a fix available, CVSS 5.3
npm:semver:20150403
Why? Mature exploit, Has a fix available, CVSS 4.3
npm:st:20171013
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: body-parser
The new version differs by 250 commits.See the full diff
Package name: cfenv
The new version differs by 3 commits.See the full diff
Package name: errorhandler
The new version differs by 85 commits.See the full diff
Package name: express
The new version differs by 250 commits.See the full diff
Package name: hbs
The new version differs by 107 commits.See the full diff
Package name: marked
The new version differs by 250 commits.See the full diff
Package name: ms
The new version differs by 19 commits.See the full diff
Package name: st
The new version differs by 32 commits.See the full diff
Package name: tap
The new version differs by 250 commits.See the full diff
Package name: validator
The new version differs by 114 commits.See the full diff
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Prototype Pollution
🦉 Cross-site Scripting (XSS)
🦉 Regular Expression Denial of Service (ReDoS)
🦉 More lessons are available in Snyk Learn